Since the files were modified, this is unlikely due to SQL injection errors.
Features for accessing files:
- Guess / steal your FTP password
- Hack the server (you can do nothing about it)
- Insufficient isolation on the server, that is, other clients can modify your files (you also can not do anything about it)
, , 2004 , , eval include , site.php?section=foo, foo.php -, 2004 . eval regex include(.*\$.*), require(.*\$.*). , .