WordPress网站"HTTP响应拆分漏洞"安全问题方案
发布时间:2019-12-16 11:14:49作者:admin点击:

function redirect_comment_link(){
$redirect = $_GET['r']; 然后在下面添加: 代码如下
$redirect = trim($redirect);
$redirect = strip_tags($redirect,""); //清除HTML等代码
$redirect = ereg_replace("\t","",$redirect); //去掉制表符号
$redirect = ereg_replace("\r\n","",$redirect); //去掉回车换行符号
$redirect = ereg_replace("\r","",$redirect); //去掉回车
$redirect = ereg_replace("\n","",$redirect); //去掉换行
$redirect = ereg_replace(" ","",$redirect); //去掉空格
$redirect = ereg_replace("'","",$redirect); //去掉单引号 保存后,如果有缓存的就生成缓存,然后再检测后看到漏洞提醒已经消失。