You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP连接MongoDB报错:MongoDB\Client类未找到问题排查

问题:NoSQL注入测试站点MongoDB连接失败排查

我正在开发一个需用户名密码登录的网站,要求密码字段存在NoSQL注入漏洞(如输入"[$ne]=1"),输入存在的用户名和该注入语句应返回“登录成功”。但目前连接MongoDB时出现错误:

Fatal error: Uncaught Error: Class "MongoDB\Client" not found in C:\wamp64\www\prac1\mongoxd.php on line 10

我已安装PHP的mongodb扩展,附上代码请求排查问题所在:

<?php

if ($_SERVER["REQUEST_METHOD"] == "POST") {
    
    $username = $_POST["username"];
    $password = $_POST["password"];

    $mongoClient = new \MongoDB\Client("mongodb://localhost:27017");

    $collection = $mongoClient->Users->users_info;
    $cursor = $collection->find(['Name' => $_GET['Name'], 'Password' => $_GET['Password']]);

    if ($cursor->count() > 0) {
        echo "Log successful";
    } else {
        echo "Error";
    }
}
?>

<!DOCTYPE html>
<html>
<head>
    <meta charset="UTF-8">
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <title>Login (Inseguro)</title>
</head>
<body>
    <h2>Login</h2>
    <form method="post" action="<?php echo htmlspecialchars($_SERVER["PHP_SELF"]); ?>">
        <label for="username">User name:</label>
        <input type="text" name="username" required><br>

        <label for="password">Password:</label>
        <input type="text" name="password" required><br>

        <input type="submit" value="Login">
    </form>
</body>
</html>

问题排查与修复

一、MongoDB\Client类找不到的解决步骤

  • 确认PHP扩展加载状态:
    1. 新建php文件调用phpinfo(),搜索mongodb关键字,确认扩展是否已成功加载。
    2. 检查WAMP的php.ini配置:确保添加了extension=mongodb(Windows环境为extension=php_mongodb.dll),配置路径无误后重启WAMP服务。
    3. 安装MongoDB PHP库:PHP的mongodb扩展仅提供底层驱动,MongoDB\Client类属于官方上层库,需通过Composer执行composer require mongodb/mongodb安装,安装后在代码开头引入自动加载文件require 'vendor/autoload.php';。

二、代码逻辑修正(保障NoSQL注入功能生效)

  • 参数获取错误:表单使用POST提交,但查询代码中错误调用了$_GET参数,需改为$_POST['username']和$_POST['password']。
  • 注入漏洞实现:直接将POST参数作为MongoDB查询条件的一部分,不做转义处理,即可让密码字段支持[$ne]=1这类注入语句(MongoDB会自动解析数组格式的查询条件)。
  • 废弃方法替换:新版MongoDB PHP库中cursor->count()已被废弃,改用countDocuments()方法统计匹配文档数。

修正后的完整代码:

<?php
require 'vendor/autoload.php'; // 引入Composer自动加载文件

if ($_SERVER["REQUEST_METHOD"] == "POST") {
    
    $username = $_POST["username"];
    $password = $_POST["password"];

    // 直接使用POST参数构造查询,实现NoSQL注入漏洞
    $query = [
        'Name' => $username,
        'Password' => $password
    ];

    $mongoClient = new \MongoDB\Client("mongodb://localhost:27017");
    $collection = $mongoClient->Users->users_info;
    
    // 用countDocuments替代废弃的count()方法
    $userCount = $collection->countDocuments($query);

    if ($userCount > 0) {
        echo "Log successful";
    } else {
        echo "Error";
    }
}
?>

<!DOCTYPE html>
<html>
<head>
    <meta charset="UTF-8">
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <title>Login (Inseguro)</title>
</head>
<body>
    <h2>Login</h2>
    <form method="post" action="<?php echo htmlspecialchars($_SERVER["PHP_SELF"]); ?>">
        <label for="username">User name:</label>
        <input type="text" name="username" required><br>

        <label for="password">Password:</label>
        <input type="text" name="password" required><br>

        <input type="submit" value="Login">
    </form>
</body>
</html>

内容的提问来源于stack exchange,提问作者Arnaupiq

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 10:17:30