֯(Dedecms)V5.X ļ©
©汾:DedeCms 5.x©:
DedeCmsѵPHPվݹϵͳ
plus/carbuyaction.phpûжԱϸĹ
©ļΪ
Include/payment/alipay.php
Include/payment/yeepay.php
©respond
Include/payment/alipay.php
......function respond(){if (!empty($_POST)){foreach($_POST as $key => $data){$_GET[$key] = $data;}}/* ļ */require_once DEDEDATA.'/payment/'.$_GET['code'].'.php';......
133ң$_GET[code]ûоκжϺˡ
Include/payment/yeepay.php
......function respond(){ /* ļ */require_once DEDEDATA.'/payment/'.$_REQUEST['code'].'.php'; $p1_MerId = trim($payment['yp_account']);$merchantKey = trim($payment['yp_key']);......
145ң$_REQUEST['code']ûоκжϺˡ<* ο
http://bugscan.net/manage/node/83
http://www.cnseay.com/2515/
*>
Է:
1.http://www.dedecms.com/plus/carbuyaction.php?dopost=return&code=../../tags ExpǰĿ¼µtags.phpļйضϣ ʹexpʱҪԼһcodealipayyeepaycookie
2.bankcodļûrespondcodebankcodʱᱩй¶·
:
Ŀǰ̻ûṩǽʹôûʱע̵ҳԻȡ°汾
http://www.dedecms.com/products/dedecms/
ʱ
1)Include/payment/alipay.php
133
require_once DEDEDATA.'/payment/'.$_GET['code'].'.php';
滻
require_once DEDEDATA.'/payment/'.basename($_GET['code']).'.php';
2) Include/payment/yeepay.php
145
require_once DEDEDATA.'/payment/'.$_REQUEST['code'].'.php';
滻
require_once DEDEDATA.'/payment/'.basename($_REQUEST['code']).'.php';
ҳ:
[1]