kppw 最新版注入(有点奇葩)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 人生第一发代码审计 ### 详细说明: 首先给厂商说句抱歉,测试demo的时候把demo搞挂了 漏洞文件:control/ajax/balance.php 看代码 ``` $arrSellerInfo = db_factory::get_one(sprintf('select * from %s a left join %s b on a.uid = b.uid where a.uid =%s',TABLEPRE.'witkey_space',TABLEPRE.'witkey_shop',intval($id))); if($arrSellerInfo['shop_backstyle']){ $arrBackgroudStyle = unserialize($arrSellerInfo['shop_backstyle']); } if($_R['a']==1){ $arr['shop_background']=""; db_factory::updatetable(TABLEPRE."witkey_shop", $arr, "uid=".$_R['id']); kekezu::show_msg('已清除','index.php?do=seller&id='.intval($id),NULL,NULL,'ok'); }elseif($_R['a']==2){ $arr['banner']=""; db_factory::updatetable(TABLEPRE."witkey_shop", $arr, "uid=".$_R['id']); kekezu::show_msg('已清除','index.php?do=seller&id='.intval($id),NULL,NULL,'ok'); } if (isset($formhash)&&kekezu::submitcheck($formhash)) { $shopObjT = keke_table_class::get_instance ( 'witkey_shop' ); $banner and $arrFields['banner'] = $banner; $background and $arrFields['shop_background'] = $background;...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息