<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>《phpwind 7.5 Multiple Include Vulnerabilities》的评论</title>
	<atom:link href="http://huaidan.org/archives/3450.html/feed" rel="self" type="application/rss+xml" />
	<link>http://huaidan.org/archives/3450.html</link>
	<description>关注网络安全</description>
	<lastBuildDate>Sun, 20 May 2012 00:27:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>作者：wpjsolo</title>
		<link>http://huaidan.org/archives/3450.html/comment-page-1#comment-19526</link>
		<dc:creator>wpjsolo</dc:creator>
		<pubDate>Wed, 24 Aug 2011 02:09:48 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3450.html#comment-19526</guid>
		<description>windows可以，但是linux不可以，并且linux貌似不可以用%00截断..</description>
		<content:encoded><![CDATA[<p>windows可以，但是linux不可以，并且linux貌似不可以用%00截断..</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：wpjsolo</title>
		<link>http://huaidan.org/archives/3450.html/comment-page-1#comment-19357</link>
		<dc:creator>wpjsolo</dc:creator>
		<pubDate>Wed, 10 Aug 2011 03:21:39 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3450.html#comment-19357</guid>
		<description>(!file_exists(R_P.&#039;api/class_&#039; . $mode . &#039;.php&#039;))
这个貌似不能包含任意目录吧，&#039;api/class_&#039;.$mode,路径里面class_指定了文件的前缀，不能直接用../来返回上一目录。</description>
		<content:encoded><![CDATA[<p>(!file_exists(R_P.'api/class_' . $mode . '.php'))<br />
这个貌似不能包含任意目录吧，'api/class_'.$mode,路径里面class_指定了文件的前缀，不能直接用../来返回上一目录。</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：now</title>
		<link>http://huaidan.org/archives/3450.html/comment-page-1#comment-19343</link>
		<dc:creator>now</dc:creator>
		<pubDate>Tue, 09 Aug 2011 07:21:04 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3450.html#comment-19343</guid>
		<description>其上放的file_exists(R_P.&#039;api/class_&#039; . $mode . &#039;.php&#039;)如何绕过此项检查。</description>
		<content:encoded><![CDATA[<p>其上放的file_exists(R_P.'api/class_' . $mode . '.php')如何绕过此项检查。</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：now</title>
		<link>http://huaidan.org/archives/3450.html/comment-page-1#comment-19335</link>
		<dc:creator>now</dc:creator>
		<pubDate>Tue, 09 Aug 2011 06:16:26 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3450.html#comment-19335</guid>
		<description>require_once(R_P.&#039;api/class_&#039; . $mode . &#039;.php&#039;);这个如何绕过？</description>
		<content:encoded><![CDATA[<p>require_once(R_P.'api/class_' . $mode . '.php');这个如何绕过？</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：seo</title>
		<link>http://huaidan.org/archives/3450.html/comment-page-1#comment-14996</link>
		<dc:creator>seo</dc:creator>
		<pubDate>Thu, 18 Mar 2010 02:15:33 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3450.html#comment-14996</guid>
		<description>呵呵
俺也看不懂 
继续学习</description>
		<content:encoded><![CDATA[<p>呵呵<br />
俺也看不懂<br />
继续学习</p>
]]></content:encoded>
	</item>
	<item>
		<title>作者：myljs</title>
		<link>http://huaidan.org/archives/3450.html/comment-page-1#comment-14632</link>
		<dc:creator>myljs</dc:creator>
		<pubDate>Wed, 03 Feb 2010 08:36:00 +0000</pubDate>
		<guid isPermaLink="false">http://huaidan.org/archives/3450.html#comment-14632</guid>
		<description>好像技术水平还不够，也可能是代码眼花。。。看不懂。。</description>
		<content:encoded><![CDATA[<p>好像技术水平还不够，也可能是代码眼花。。。看不懂。。</p>
]]></content:encoded>
	</item>
</channel>
</rss>

