xpshop系统sql盲注一处

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: ### 详细说明: 漏洞位置:xpshop.webui.checkout ``` protected void Page_Load(object sender, EventArgs e) { this.sid = Utils.ReqIntParams("sid", -1); if (base.CurrentUser == null) { base.Response.Redirect(string.Concat(new object[] { "Login.aspx?ReturnUrl=/", WebUIBase.ShopFolder, "Checkout.aspx?sid=", this.sid })); } else { string text = Utils.ReqStrParams("type", ""); string text2 = Utils.ReqStrParams("Action", ""); if (text.Length > 0 && text2.Length > 0) { string text3 = text2; if (text3 != null) { if (!(text3 == "GetZtds")) { if (!(text3 == "GetShipps")) { if (!(text3 == "GetShoppingCart")) { if (!(text3 == "GetAdvancePayment")) { if (!(text3 == "UseCoupon")) { if (text3 == "CancleCoupon") { this.CancleCoupon(); } } else { this.UseCoupon(); } } else if (base.CurrentUser != null && base.CurrentUser.Name != "anonymous") { this.Session["CurrentUser"] = this.memberDB.GetMemberDetails(base.CurrentUser.MemberID); base.Response.Write(base.CurrentUser.AdvancePayment); } else {...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息