成都公司:成都市成华区建设南路160号1层9号
重庆公司:重庆市江北区红旗河沟华创商务大厦18楼
ECshop屏蔽SQL提示具体操作
- function ErrorMsg($message = '', $sql = '')
- {
- if ($message)
- {
- echo "<b>ECSHOP info</b>: $messagenn<br /><br />";
- //print('<a href="http://faq.comsenz.com/?type=mysql&dberrno=2003&dberror=Can%27t%20connect%20to%20MySQL%20server%20on" target="_blank">http://faq.comsenz.com/</a>');
- }
- else
- {
- echo "<b>MySQL server error report:";
- print_r($this->error_message);
- //echo "<br /><br /><a href='http://faq.comsenz.com/?type=mysql&dberrno=" . $this->error_message[3]['errno'] . "&dberror=" . urlencode($this->error_message[2]['error']) . "' target='_blank'>http://faq.comsenz.com/</a>";
- }
- exit;
- }
修改为
- function ErrorMsg($message = '', $sql = '')
- {
- if ($message)
- {
- //echo "<b>ECSHOP info</b>: $messagenn<br /><br />";
- //print('<a href="http://faq.comsenz.com/?type=mysql&dberrno=2003&dberror=Can%27t%20connect%20to%20MySQL%20server%20on" target="_blank">http://faq.comsenz.com/</a>');
- }
- else
- {
- //echo "<b>MySQL server error report:";
- //print_r($this->error_message);
- //echo "<br /><br /><a href='http://faq.comsenz.com/?type=mysql&dberrno=" . $this->error_message[3]['errno'] . "&dberror=" . urlencode($this->error_message[2]['error']) . "' target='_blank'>http://faq.comsenz.com/</a>";
- }
- exit;
- }
把所有的错误输出屏蔽 这样很方便的就解决了注入问题

