瀏覽代碼

sql注入问题

sgjj 5 年之前
父節點
當前提交
b03b44a3c6
共有 1 個文件被更改,包括 3 次插入0 次删除
  1. 3 0
      src/main/java/net/mingsoft/cms/action/web/MCmsAction.java

+ 3 - 0
src/main/java/net/mingsoft/cms/action/web/MCmsAction.java

@@ -200,6 +200,9 @@ public class MCmsAction extends net.mingsoft.cms.action.BaseAction {
 				return;
 			}
 		}
+		if(sqlFilter(orderby)){
+			orderby = "id";
+		}
 		PageBean page = new PageBean();
 		//根据文章编号查询栏目详情模版
 		CategoryEntity column = (CategoryEntity) categoryBiz.getEntity(Integer.parseInt(article.getContentCategoryId()));