xercms...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

sql注入在D:\wamp\www\XerCMS\Modules\member\index.php中的upfiles函数 ``` public function upfiles() { setformat('json'); $config = ini('member/group/'.X::$G['group']); if(empty($config)) { exit('Access Denied'); } else { if($config['upload'][0] == 0) { error('upload_group_limit'); } else if($config['upload'][1] != 0 && X::$G['upload'] > $config['upload'][1]) { error('upload_group_size'); } } $id = int1(g('id')); c('upload')->load($id); $image = ini('image'); if(isset($image['status']{2})) { c('upload')->config['thumbs'] = array(array('width'=>$image['width'],'height'=>$image['height'],'cut'=>$image['cut'],'quality'=>$image['quality'])); } else { if(isset(c('upload')->config['thumbs'])) unset(c('upload')->config['thumbs']); } c('upload')->files(); c('upload')->show(); } ``` 其中这行 ``` c('upload')->files(); ``` 有问题,跟一下该files函数,位于D:\wamp\www\XerCMS\Library\XerCMS_upload.php中 ``` function files() { foreach($_FILES as $k=>$v) { $this->file($k); } } ``` 可以看到进行了文件的相关操作:$_FILES...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息