kppw最新版任意用户登录

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 只需要用户名和用户id即可实现任意用户登录 ### 详细说明: 问题出在 lib/inc/keke_core_class.php function init_user() 第981行 ``` elseif ($_COOKIE ['keke_auto_login']) { $loginInfo = unserialize ( $_COOKIE ['keke_auto_login'] ); $pwdInfo = explode ( '|', base64_decode ( $loginInfo [2] ) ); $uInfo = kekezu::get_table_data ( '*', 'witkey_space', " username='$pwdInfo[2]' and password = '$pwdInfo[1]'", '', '' ); if ($uInfo [0] ['uid'] == $pwdInfo [0]) { $_SESSION ['uid'] = $uInfo [0] ['uid']; $_SESSION ['username'] = $uInfo [0] ['username']; $this->_uid = $_SESSION ['uid']; $this->_username = $uInfo [0] ['username']; } } ``` $uInfo = kekezu::get_table_data ( '*', 'witkey_space', " username='$pwdInfo[2]' and password = '$pwdInfo[1]'", '', '' ); 此处两个变量都来自$pwdInfo $pwdInfo = explode ( '|', base64_decode ( $loginInfo [2] ) ); 继续跟进 $loginInfo = unserialize ( $_COOKIE ['keke_auto_login'] ); 全程无安全处理,现在来看看$_COOKIE['keke_auto_login']的格式 正常情况下在登录处勾选记住我...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息