Webhacking.kr old-46
SQL injection 문제다. include "../../config.php"; if($_GET['view_source']) view_source();?>SQL INJECTIONlevel : view-source if($_GET['lv']){ $db = dbconnect(); $_GET['lv'] = addslashes($_GET['lv']); $_GET['lv'] = str_replace(" ","",$_GET['lv']); $_GET['lv'] = str_replace("/","",$_GET['lv']); $_GET['lv'] = str_replace("*","",$_GET['lv']); $_GET['lv'] = str_replace("%","",$_GET[..