What should I do to resolve the global authentication security problem that occurs after PHP is scanned with AppScan?
GET edit_info.php?username=18511333333&gender= "&birthday=1996-03-02 http/1.1
Accept:application/x-ms-application, Image/jpeg, Application/xaml+xml, Image/gif, Image/pjpeg, application/ X-MS-XBAP, */*
Accept-language:zh-cn
user-agent:mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; trident/4.0;. NET CLR 2.0.50727; SLCC2;. NET CLR 3.5.30729;. NET CLR 3.0.30729; Media Center PC 6.0; Tablet PC 2.0)
Connection:keep-alive
Host:cqc.xunsmart.com
http/1.1 OK
Connection:close
Date:sat, 16:44:31 GMT
server:microsoft-iis/6.0
X-powered-by:asp.net
x-powered-by:php/5.2.17
Content-type:text/html
? {"Status": "OK", "MSG": "\u4fee\u6539\u6210\u529f!", "data": [{"UID": "username": "18511333333", "Password": " 25f9e794323b453885f5181f1b624d0b "," myname ":" Gan
------to solve the idea----------------------
Looks like it's asking for this address. Returns some key information about the user (even including the password)
------to solve the idea----------------------
Do not believe in the so-called expert's alarmist conclusion, you have confidence in yourself
Do not arbitrarily attach to the URL should not be public information, as far as possible to use post or put to pass the data