登录页面:
登录页面处理:
= ['loginname' = ['username' = ['password' = (['vcode' = (['rcode'("localhost", "root", "111"("mymessbox"("set names utf8" ( !== "<script>alert('the code is wrong!');window.location.href='login.php'</script>" ( == 'manager' = "select username,password from manager where username='' and password=''" = ( = ( ( >=1['mgusername'] = "<script>alert('login success!');window.location.href='./manager/mg_index.php'</script>" "<script>alert('Login failed!The username or password was wrong!Please login again!');window.location.href='login.php'</script>" = "select username,password from user where username='' and password=''" = ( = ( ( >=1['username'] = "<script>alert('login success!');window.location.href='./user/index.php'</script>" "<script>alert('Login failed!The username or password was wrong!!Please login again!');window.location.href='login.php'</script>" loginok.php先发这两个吧,虽然还没有完成,还有很多漏洞百出的地方,但是我会一点一点去改。
希望哪个大神在看的时候,能多多指点。不胜感激!