打开 对应的php 文件. 下面是密码更新语句. 如果我们把 "UPDATE users SET PASSWORD='$pass' where username='$username' and password='$curr_pass' "; 改为:"UPDATE users SET PASSWORD='$pass' where username='admin'#' and password='$curr_pass' "; 可以发现admin' 和前面闭合起来成一个语句。 # 注释掉后面的语句了.
if($pass==$re_pass) { $sql = "UPDATE users SET PASSWORD='$pass' where username='$username' and password='$curr_pass' "; $res = mysql_query($sql) ordie('You tried to be smart, Try harder!!!! :( '); $row = mysql_affected_rows(); echo'<font size="3" color="#FFFF00">'; echo'<center>';