espcms最新版两处高危SQL注入漏洞附分析(遗漏未修复)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 绝对是最新版本! 版本信息:V6.4.15.08.25 UTF8 正式版 更新时间:2015-08-25 12:29:04 软件大小:7.67MB 25号更新的,有两处高危注入没有修复 ### 详细说明: 第一处在 在enquiry.php中 ``` $ptitle = $this->fun->accept('ptitle', 'P'); $tsn = $this->fun->accept('tsn', 'P'); $did = $this->fun->accept('did', 'P'); if (empty($did) || empty($amount) || empty($ptitle)) { $enquirylink = $this->get_link('enquiry', array(), admin_LNG); $this->callmessage($this->lng['enquiry_input_err'], $enquirylink, $this->lng['enquiry_into_listbotton']); } if (!preg_match("/^\w+((-\w+)|(\.\w+))*\@[A-Za-z0-9]+((\.|-)[A-Za-z0-9]+)*\.[A-Za-z0-9]+$/i", $email)) { $this->callmessage($this->lng['email_err'], $_SERVER['HTTP_REFERER'], $this->lng['gobackbotton']); } $enquirysn = date('YmdHis') . rand(100, 9999); $db_table = db_prefix . 'enquiry'; $db_table2 = db_prefix . 'enquiry_info'; $addtime = time(); $db_field = 'enquirysn,userid,linkman,sex,country,province,city,district,address,zipcode,tel,fax,mobile,email,content,isclass,addtime,edittime'; $db_values =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息