system.func.php 1.4 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546
  1. <?php
  2. /**
  3. * [WeEngine System] Copyright (c) 2014 WE7.CC
  4. * WeEngine is NOT a free software, it under the license terms, visited http://www.we7.cc/ for more details.
  5. */
  6. if(!function_exists('getglobal')) {
  7. function getglobal($key) {
  8. global $_W;
  9. $key = explode('/', $key);
  10. $v = &$_W;
  11. foreach ($key as $k) {
  12. if (!isset($v[$k])) {
  13. return null;
  14. }
  15. $v = &$v[$k];
  16. }
  17. return $v;
  18. }
  19. }
  20. if (!function_exists('strip_gpc')) {
  21. function strip_gpc($values, $type = 'g') {
  22. $filter = array(
  23. 'g' => "'|(and|or)\\b.+?(>|<|=|in|like)|\\/\\*.+?\\*\\/|<\\s*script\\b|\\bEXEC\\b|UNION.+?SELECT|UPDATE.+?SET|INSERT\\s+INTO.+?VALUES|(SELECT|DELETE).+?FROM|(CREATE|ALTER|DROP|TRUNCATE)\\s+(TABLE|DATABASE)",
  24. 'p' => "\\b(and|or)\\b.{1,6}?(=|>|<|\\bin\\b|\\blike\\b)|\\/\\*.+?\\*\\/|<\\s*script\\b|\\bEXEC\\b|UNION.+?SELECT|UPDATE.+?SET|INSERT\\s+INTO.+?VALUES|(SELECT|DELETE).+?FROM|(CREATE|ALTER|DROP|TRUNCATE)\\s+(TABLE|DATABASE)",
  25. 'c' => "\\b(and|or)\\b.{1,6}?(=|>|<|\\bin\\b|\\blike\\b)|\\/\\*.+?\\*\\/|<\\s*script\\b|\\bEXEC\\b|UNION.+?SELECT|UPDATE.+?SET|INSERT\\s+INTO.+?VALUES|(SELECT|DELETE).+?FROM|(CREATE|ALTER|DROP|TRUNCATE)\\s+(TABLE|DATABASE)",
  26. );
  27. if (!isset($values)) {
  28. return '';
  29. }
  30. if(is_array($values)) {
  31. foreach($values as $key => $val) {
  32. $values[addslashes($key)] = strip_gpc($val, $type);
  33. }
  34. } else {
  35. if (preg_match("/".$filter[$type]."/is", $values, $match) == 1) {
  36. $values = '';
  37. }
  38. }
  39. return $values;
  40. }
  41. }