xpshop网店系统sql注入两处(一处盲注)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: ### 详细说明: 漏洞位置:**.**.**.**order ``` protected void Page_Load(object sender, EventArgs e) { if (base.CurrentUser != null && base.CurrentUser.Name != "anonymous") { this.member = base.CurrentUser; this.shipfree = new ShippingFreeDB().GetShippingFreeDetails(1); if (!base.IsPostBack) { if (base.Request.QueryString["type"] != null && base.Request.QueryString["Action"] != null) { string text = base.Request.QueryString["Action"]; if (text != null) { if (!(text == "GetSubArea")) { if (!(text == "GetAddrDetail")) { if (!(text == "GetZtds")) { if (!(text == "GetShipps")) { if (!(text == "GetShoppingCart")) { if (text == "GetAdvancePayment") { if (base.CurrentUser != null && base.CurrentUser.Name != "anonymous") { base.Response.Write(base.CurrentUser.AdvancePayment); } else { base.Response.Write("0"); } } } else { ShoppingCartDB shoppingCartDB = new ShoppingCartDB(); SqlDataReader items = shoppingCartDB.GetItems(shoppingCartDB.GetShoppingCartId()); string s =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息