Follow along with the video below to see how to install our site as a web app on your home screen.
Бележка: This feature may not be available in some browsers.
излиза си сичко като трябва да си е ??federer_11 каза:не е ли така index.php?id=2'
<?php
include("config.php");
$id = trim(htmlspecialchars(addslashes($_GET['id'])));
$sql = mysql_query("SELECT * from `gallery` WHERE `id`='$id'");
while($row = mysql_fetch_array($sql)) {
$title = $row['title'];
$avtor = $row['avtor'];
$snimka = $row['snimka'];
$uid = $row['uid'];
$info = $row['info'];
$data = $row['data'];
echo '
<center>
';
echo "<h2>$title</h2>";
echo '<a href="'.$snimka.'" rel="lightbox" alt="'.$snimka.'"><img src="'.$snimka.'" width="450" height="400" alt="'.$snimka.'" /></a><br />';
echo 'Описание:<br>'. addslashes(strip_tags(htmlspecialchars($info)));
echo "<div class='hr'></div><img src='img/user.gif'> <a href=\"./forum/memberlist.php?mode=viewprofile&u=$uid\">$avtor</a>";
echo '</a> - на '.addslashes(strip_tags(htmlspecialchars($data)));
echo '</center>';
}
?>
<?php
include("config.php");
$id = int($_GET['id']);
$sql = mysql_query("SELECT * from `gallery` WHERE `id`='$id'");
while($row = mysql_fetch_array($sql)) {
$title = $row['title'];
$avtor = $row['avtor'];
$snimka = $row['snimka'];
$uid = $row['uid'];
$info = $row['info'];
$data = $row['data'];
echo '<center>';
echo "<h2>$title</h2>";
echo '<a href="'.$snimka.'" rel="lightbox" alt="'.$snimka.'"><img src="'.$snimka.'" width="450" height="400" alt="'.$snimka.'" /></a><br />';
echo 'Описание:<br> $info';
echo "<div class='hr'></div><img src='img/user.gif'> <a href=\"./forum/memberlist.php?mode=viewprofile&u=$uid\">$avtor</a>";
echo '</a> - на $data';
echo '</center>';
}
?>
на тези не ли хубаво да се сложи addslashes?$title = $row['title'];
$avtor = $row['avtor'];
$snimka = $row['snimka'];
$uid = $row['uid'];
$info = $row['info'];
$data = $row['data'];
porkie каза:излиза си сичко като трябва да си е ??federer_11 каза:не е ли така index.php?id=2'
porkie каза:на тези не ли хубаво да се сложи addslashes?$title = $row['title'];
$avtor = $row['avtor'];
$snimka = $row['snimka'];
$uid = $row['uid'];
$info = $row['info'];
$data = $row['data'];
Трябва да четеш повече.KlaXeN каза:СЛАГА СЕ \ не 2' :wink:
1). Check for vulnerability
Let's say that we have some site like this
http://www.site.com/news.php?id=5
Now to test if is vulrnable we add to the end of url ' (quote),
and that would be http://www.site.com/news.php?id=5'
so if we get some error like
"You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right etc..."
or something similar
that means is vulrnable to sql injection![]()