KPPW最新版一处函数七处注入附送后台任意文件删除两枚加注入一枚

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: SQL. ### 详细说明: 问题出现在 \lib\sys\keke_shop_release_class.php 的save_service_obj函数中 部分代码如下 ``` public function save_service_obj($release_info = array(), $obj_name) { global $kekezu; if ($release_info ['step1'] == 'step1') { if ($_POST ['fileid1']) { $fileIdArr = explode('|', $_POST ['fileid1']); if(is_array($fileIdArr)){ $fileIdStr = implode(',', $fileIdArr); $filePathArr = db_factory::query('select save_name from '.TABLEPRE.'witkey_file where file_id in ('.$fileIdStr.')'); if($filePathArr){ foreach ($filePathArr as $v) { $filePathStr.=','.$v['save_name']; } $filePathStr = substr($filePathStr, 1); $pic = kekezu::escape ( $filePathStr ); $release_info ['pic_patch'] = $pic; } }else{ $filePathArr = db_factory::get_one('select save_name from '.TABLEPRE.'witkey_file where file_id = '.intval($_POST ['fileid1'])); $filePathStr = $filePathArr['save_name']; $pic = kekezu::escape ( $filePathStr ); $release_info ['pic_patch'] = $pic; } } } empty ( $release_info ) or...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息