emlog相册插件 kl_album_ajax_do.php SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

来自[http://www.leavesongs.com/PENETRATION/emlog-important-plugin-getshell.html] 检查EM相册插件源代码,看到kl_album_ajax_do.php: ``` <?php /** * kl_album_ajax_do.php * design by KLLER */ require_once('../../../init.php'); $DB = MySql::getInstance(); $kl_album_config = unserialize(Option::get('kl_album_config')); if(isset($_POST['album']) && isset($_FILES['Filedata'])){ if(function_exists('ini_get')){ $kl_album_memory_limit = ini_get('memory_limit'); $kl_album_memory_limit = substr($kl_album_memory_limit, 0, strlen($kl_album_memory_limit)-1); $kl_album_memory_limit = ($kl_album_memory_limit+20).'M'; ini_set('memory_limit', $kl_album_memory_limit); } define('KL_UPLOADFILE_MAXSIZE', kl_album_get_upload_max_filesize()); define('KL_UPLOADFILE_PATH', '../../../content/plugins/kl_album/upload/'); define('KL_IMG_ATT_MAX_W',100);//图片附件缩略图最大宽 define('KL_IMG_ATT_MAX_H',100);//图片附件缩略图最大高 $att_type = array('jpg', 'jpeg', 'png', 'gif');//允许上传的文件类型 $album = isset($_POST['album']) ? intval($_POST['album']) :...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息