PHPMPS v2.3 /member.php SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

<ul><li>/member.php</li></ul><pre class="">case 'send': $paycenter = trim($_POST['paycenter']); $contactname = trim($_POST['contactname']); $telephone = trim($_POST['telephone']); $email = trim($_POST['email']); $username = trim($_POST['username']); $orderid = trim($_POST['orderid']); $time = time(); $ip = get_ip(); $payonline_setting = get_pay_setting(); array_key_exists($paycenter, $payonline_setting) or showmsg('不存在此支付方式'); @extract($payonline_setting[$paycenter]); setcookie('paycenter', $paycenter, time() + 3600*24*365); $r = $db-&gt;getOne("SELECT payid FROM {$table}pay_online WHERE `orderid`='$orderid'"); if($r) showmsg('不要刷新'); $moneytype = 'CNY'; $amount = floatval($_POST['amount']); $trade_fee = floatval($_POST['trade_fee']); $db-&gt;query("INSERT INTO {$table}pay_online (`paycenter`,`username`,`orderid`,`moneytype`,`amount`,`trade_fee`,`contactname`,`telephone`,`email`,`sendtime`,`ip`)...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息