diff --git a/admin/admin.db b/admin/admin.db index 4be7840..ae189f6 100755 Binary files a/admin/admin.db and b/admin/admin.db differ diff --git a/classesphp/pega_variaveis.php b/classesphp/pega_variaveis.php index 05b90e3..1db46f7 100755 --- a/classesphp/pega_variaveis.php +++ b/classesphp/pega_variaveis.php @@ -60,7 +60,7 @@ if (basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME'])){ } error_reporting(0); -$bl = array("_decode","php","eval","passthru","shell_exec","escapeshellarg","escapeshellcmd","proc_close","proc_open","dl","popen","contents","delete","drop","update","insert","exec","system",";"); +$bl = array("password","select","_decode","php","eval","passthru","shell_exec","escapeshellarg","escapeshellcmd","proc_close","proc_open","dl","popen","contents","delete","drop","update","insert","exec","system",";"); if (isset($_GET)) { foreach(array_keys($_GET) as $k) diff --git a/classesphp/sani_request.php b/classesphp/sani_request.php index 5423ccb..9bd0511 100755 --- a/classesphp/sani_request.php +++ b/classesphp/sani_request.php @@ -3,7 +3,7 @@ if (basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME'])){ exit; } error_reporting(0); -$bl = array("_decode","php","eval","passthru","shell_exec","escapeshellarg","escapeshellcmd","proc_close","proc_open","dl","popen","contents","delete","drop","update","insert","exec","system",";"); +$bl = array("password","select","_decode","php","eval","passthru","shell_exec","escapeshellarg","escapeshellcmd","proc_close","proc_open","dl","popen","contents","delete","drop","update","insert","exec","system",";"); if (isset($_GET)){ foreach(array_keys($_GET) as $k) { $k = str_ireplace($bl,"",$k); diff --git a/ferramentas/vinde/wmsindejson.php b/ferramentas/vinde/wmsindejson.php index b062a22..7619483 100755 --- a/ferramentas/vinde/wmsindejson.php +++ b/ferramentas/vinde/wmsindejson.php @@ -26,6 +26,7 @@ if(!file_exists($arq)){ else{ $resultado = file_get_contents($arq); } +$resultado = str_replace("