Phpwind的v4/5/6/7/8命令执行漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 07年那阵挖掘的漏洞,正好这次三个白帽搞了个挑战,借这个机会曝光吧,外面估计也有部分人知道这个吧:) ### 详细说明: hack/bank/index.php ``` $_DDESPOSTDB=array(); $query=$db->query("SELECT i.uid,username,ddeposit,dstartdate FROM pw_memberinfo i LEFT JOIN pw_members m ON m.uid=i.uid ORDER BY ddeposit DESC LIMIT $bk_num"); while($deposit=$db->fetch_array($query)){ if($deposit['ddeposit']){ $deposit['dstartdate']=get_date($deposit['dstartdate']); $_DDESPOSTDB[]=array($deposit['uid'],$deposit['username'],$deposit['ddeposit'],$deposit['dstartdate']); } } $wirtedb=savearray('_DESPOSTDB',$_DESPOSTDB); $wirtedb.="\n".savearray('_DDESPOSTDB',$_DDESPOSTDB); writeover(D_P.'data/bbscache/bank_sort.php',"<?php\r\n".$wirtedb.'?>'); } ... function savearray($name,$array){ $arraydb="\$$name=array(\r\n\t\t"; foreach($array as $value1){ $arraydb.='array('; foreach($value1 as $value2){ $arraydb.='"'.addslashes($value2).'",'; } $arraydb.="),\r\n\t\t"; } $arraydb.=");\r\n"; return $arraydb; } ```...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息