xpshop网店系统sql注入(官网demo演示)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: ### 详细说明: 漏洞位置:xpshop.webui.MyRefund ``` protected void Page_Load(object sender, EventArgs e) { if (base.CurrentUser == null) { string str = "Login.aspx?ReturnUrl=/" + WebUIBase.ShopFolder + "MyRefund.aspx"; base.Response.Redirect("/" + WebUIBase.ShopFolder + str); } else { if (base.CurrentUser.Name == "anonymous") { string str = "index." + this.config.html; base.Response.Write(base.GetResourceString("MsgPleaseSignInFirst")); base.Response.Write(Utils.Redirect("/" + WebUIBase.ShopFolder + str)); } if (!base.IsPostBack) { if (base.Request.QueryString["type"] != null && base.Request.QueryString["Action"] != null) { string text = base.Request.QueryString["Action"]; if (text != null && text == "GetProducts") { this.GetProducts(); } base.Response.End(); } ``` 跟进函数GetProducts: private void GetProducts() { string orderNo = base.Request.QueryString["OrderNo"]; OrderDB orderDB = new OrderDB(); int orderID = orderDB.GetOrderID(orderNo, base.CurrentUser.MemberID); string text; if...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息