Takas Classified 1.1 - SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

controllers/Classified_ads.php文件的subcatid,catid,locid,areaid,type,post参数带入SQL语句导致SQL注入的产生 SQL 注入点: http://localhost/[PATH]/index.php/classified_ads/ads/?&subcatid=[SQL] ![](https://images.seebug.org/contribute/95b675bb-696c-4ba9-a4f3-3f92e8b9dcd0) ![](https://images.seebug.org/contribute/f8db9a96-30c7-4df8-ba81-46408ee59ec9) http://localhost/[PATH]/index.php/classified_ads/ads/?&locid=[SQL] ![](https://images.seebug.org/contribute/976667e9-d322-4cc8-9cba-aba34a3ddeab) http://localhost/[PATH]/index.php/classified_ads/ads/?&catid=[SQL] http://localhost/[PATH]/index.php/classified_ads/ads/?&areaid=[SQL] http://localhost/[PATH]/index.php/classified_ads/ads/?&type=[SQL] http://localhost/[PATH]/index.php/classified_ads/ads/?&post=[SQL]

0%
暂无可用Exp或PoC
当前有0条受影响产品信息