Open
Conversation
- 在 if_login() 函数中使用预处理语句替换危险的字符串拼接 - 将模糊匹配(LIKE)改为精确匹配(=)提高安全性 - 修复身份验证绕过漏洞,防止 SQL 注入攻击 验证结果: - 使用 SQLMap 测试确认注入漏洞已修复 - 用户查询功能正常工作
- 在 login() 函数中使用预处理语句替换危险的字符串拼接 - 使用参数化查询防止用户输入直接拼接到 SQL 语句中 - 修复身份验证绕过漏洞,防止 SQL 注入攻击 验证结果: - 使用 SQLMap 测试确认注入漏洞已修复 - 用户登录功能正常工作 - 密码验证和会话设置逻辑保持正常"
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
验证结果: