您的网站发现个高危漏洞,请尽快修复,避免严重损失
if(empty($rowcontrol[ifshell])){
$testv="yes";
$dirarr=array("img/",
returnjgdw($rowcontrol[addir],"","gg")."/",
"ckeditor/attached/",
"config/ueditor/php/upload/",
"config/ueditor/php/upload1/",
"config/ueditor/php/upload2/",
"config/ueditor/php/upload3/",
"config/ueditor_mini/php/upload/",
"config/ueditor_mini/php/upload1/",
"config/ueditor_mini/php/upload2/",
"config/ueditor_mini/php/upload3/",
"upload/"
);
for($i=0;$i
- 修复方法
- 文件夹:=$dirarr[$i]?> 存在可执行脚本权限漏洞,有被注入并运行木马的风险
}}}else{?>
- 启动检测
- 您的后台关闭了 [脚本执行权限检测开关],如果确保该类漏洞已经修复,可忽略本条提示
$errnum++;}?>
while1("*","yjcode_admin where adminuid='".$_SESSION["SHOPADMIN"]."'");$row1=mysql_fetch_array($res1);
if(strcmp("admin",$row1[adminuid])==0){$errnum++;
?>
- 立即修复
- 请不要采用admin之类的容易被猜到的字符做为管理员账号
}?>
if(strcmp(sha1("admin"),$row1[adminpwd])==0 || strcmp(sha1("123456"),$row1[adminpwd])==0 || strcmp(sha1("admin888"),$row1[adminpwd])==0){$errnum++;
?>
- 立即修复
- 请不要采用admin、123456、admin888之类的容易被猜到的字符做为密码
}?>
if(@htmlget(weburl."config/conn.php?id=1%20and%201=1")=="4004"){$errnum++;
?>
- 点击修复
- 您的主机/服务器未安装网站安全防护软件,建议安装,避免遭受攻击
}?>
待办事项和数据统计
$anum=returncount("yjcode_user where shopzt=1");?>
$anum=returncount("yjcode_baomoneyrecord where zt=1");?>
$anum=returncount("yjcode_tixian where zt=4");?>
$anum=returncount("yjcode_user where sfzrz=0");?>
$anum=returncount("yjcode_payreng where ifok=1");?>
$anum=returncount("yjcode_user");?>
$anum=returncount("yjcode_pro where zt=1");?>
$anum=returncount("yjcode_pro where zt<>99");?>
$anum=returncount("yjcode_server where zt=1");?>
$anum=returncount("yjcode_order where ddzt='wait'");?>
$anum=returncount("yjcode_order where ddzt='jf'");?>
$anum=returncount("yjcode_jubao where zt=1");?>
$anum=returncount("yjcode_news where zt=1");?>
$anum=returncount("yjcode_task where zt=1 and taskty=0");?>
$anum=returncount("yjcode_task where zt=1 and taskty=1");?>
$anum=returncount("yjcode_task where zt=8");?>
$anum=returncount("yjcode_gd where gdzt=1 and zt<>99");?>
$anum=returncount("yjcode_newspj where zt=1");?>