對比官方更新的內容,織夢DedeCMS官方2013年6月7號完成的安全補丁主要更新的文件是include/dedesql.class.php,修復變量覆蓋漏洞。我們對比之前版本的include/dedesql.class.php文件,會發現最新的include/dedesql.class.php文件會多出第588到第592行的那幾段代碼(也可以復制以下一小段代碼進行搜索),代碼大致如下:
						 
					$arrs1 = array(0x63,0x66,0x67,0x5f,0x70,0x6f,0x77,0x65,0x72,0x62,0x79);
					$arrs2 = array(0x20,0x3c,0x61,0x20,0x68,0x72,0x65,0x66,0x3d,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,
					0x77,0x77,0x77,0x2e,0x64,0x65,0x64,0x65,0x63,0x6d,0x73,0x2e,0x63,0x6f,0x6d,0x20,0x74,0x61,0x72,
					0x67,0x65,0x74,0x3d,0x27,0x5f,0x62,0x6c,0x61,0x6e,0x6b,0x27,0x3e,0x50,0x6f,0x77,0x65,0x72,0x20,
					0x62,0x79,0x20,0x44,0x65,0x64,0x65,0x43,0x6d,0x73,0x3c,0x2f,0x61,0x3e);