|
打开Kesion.CommonCls.asp找到大概1195行(标红色的)- Dim objRegExp, Match, Matches
- Set objRegExp = New Regexp
- objRegExp.IgnoreCase = True
- objRegExp.Global = True
- objRegExp.Pattern = "<.+?>"
- Set Matches = objRegExp.Execute(ContentStr)
- For Each Match in Matches
- ContentStr=Replace(ContentStr,Match.Value,"")
- Next
- objRegExp.Pattern = "\[.+?\]"
- Set Matches = objRegExp.Execute(ContentStr)
- For Each Match in Matches
- ContentStr=Replace(ContentStr,Match.Value,"")
- Next
- LoseHtml=ContentStr
- Set objRegExp = Nothing
改为:- Dim objRegExp, Match, Matches
- Set objRegExp = New Regexp
- objRegExp.IgnoreCase = True
- objRegExp.Global = True
- objRegExp.Pattern = "<.+?>"
- Set Matches = objRegExp.Execute(ContentStr)
- For Each Match in Matches
- ContentStr=Replace(ContentStr,Match.Value,"")
- Next
- objRegExp.Pattern = "<\/*[^<>]*>"
- Set Matches = objRegExp.Execute(ContentStr)
- For Each Match in Matches
- ContentStr=Replace(ContentStr,Match.Value,"")
- Next
- LoseHtml=ContentStr
- Set objRegExp = Nothing
我也不知道这是什么意思,改了不知道会不会出现漏洞,还需要官方解释呢
|