方维众筹系统SQL注入漏洞一

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 方维众筹系统SQL注入漏洞一 ### 详细说明: 1.首先定位到漏洞文件。app\Lib\modules\accountModule.class.php。 ``` public function get_leader_list(){ if(!$GLOBALS['user_info']) app_redirect(url("user#login")); $deal_id=$_REQUEST['id'];//这里的id没有经过过滤 $deal=$GLOBALS['db']->getRow("select * from ".DB_PREFIX."deal where id=$deal_id and user_id=".$GLOBALS['user_info']['id']); $page_size = ACCOUNT_PAGE_SIZE; $page = intval($_REQUEST['p']); if($page==0) $page = 1; $limit = (($page-1)*$page_size).",".$page_size; $investor_list=$GLOBALS['db']->getAll("select invest.*,u.user_name,u.user_level from ".DB_PREFIX."investment_list as invest left join ".DB_PREFIX."user as u on u.id=invest.user_id where invest.type=1 and invest.deal_id=$deal_id order by invest.id desc limit $limit "); $investor_list_num=$GLOBALS['db']->getOne("select count(*) as num from ".DB_PREFIX."investment_list where type=1 and deal_id=$deal_id order by id desc limit $limit "); $now_time=NOW_TIME; foreach($investor_list as $k=>$v){...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息