时间:2020-04-26 22:09:13 | 栏目: | 点击:次
if(empty(${$_key."_size"}))
{
${$_key."_size"} = @filesize($$_key);
}
$imtypes = array("image/pjpeg", "image/jpeg", "image/gif", "image/png", "image/xpng", "image/wbmp", "image/bmp");
if(in_array(strtolower(trim(${$_key."_type"})), $imtypes)){
$image_dd = @getimagesize($$_key); if($image_dd == false){
continue;
}
if (!is_array($image_dd)) {
exit("Upload filetype not allow !");
}
}
$image_dd = @getimagesize($$_key);
if($image_dd == false){ continue; }
添加完成后保存并替换原来的文件即可,操作完成后就可以去阿里云后台验证这个漏洞了。