From a8a928fee7d2b8780697d46f6d9fa50b45675974 Mon Sep 17 00:00:00 2001 From: midoks Date: Mon, 27 Jun 2022 13:37:14 +0800 Subject: [PATCH] =?UTF-8?q?=E9=81=BF=E5=85=8Dphpmyadmin=E6=97=A0=E6=B3=95?= =?UTF-8?q?=E7=99=BB=E5=BD=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- plugins/op_waf/waf/lua/init.lua | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/plugins/op_waf/waf/lua/init.lua b/plugins/op_waf/waf/lua/init.lua index 04a6384d4..60d1bf45f 100644 --- a/plugins/op_waf/waf/lua/init.lua +++ b/plugins/op_waf/waf/lua/init.lua @@ -317,26 +317,35 @@ function post_data_chekc() if C:return_post_data() then return false end request_args = ngx.req.get_post_args() if not request_args then return false end - if not request_header['Content-Type'] then return false end - av=string.match(request_header['Content-Type'],"=.+") + + if request_header then + if not request_header['Content-Type'] then return false end + av = string.match(request_header['Content-Type'],"=.+") + end + if not av then return false end - ac=split(av,'=') + ac = split(av,'=') + if not ac then return false end + list_list=nil for i,v in ipairs(ac) do list_list='--'..v end + if not list_list then return false end aaa=nil for k,v in pairs(request_args) do aaa=v end + if not aaa then return false end if tostring(aaa) == 'true' then return false end if type(aaa) ~= "string" then return false end data_len=split(aaa,list_list) + --return return_message(200,data_len) if not data_len then return false end if arrlen(data_len) ==0 then return false end