漏洞在web/source/site/article.ctrl.php,修复方法(代码在81行左右)
搜索
if (empty($_GPC['title'])) {
message('标题不能为空,请输入标题!');
}
在后面增加代码
mysql_set_charset("gbk"); $_GPC['template'] = mysql_real_escape_string($_GPC['template']); $_GPC['title'] = mysql_real_escape_string($_GPC['title']); $_GPC['description'] = mysql_real_escape_string($_GPC['description']); $_GPC['source'] = mysql_real_escape_string($_GPC['source']); $_GPC['author'] = mysql_real_escape_string($_GPC['author']);