cmseasy最新版 一枚注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 可惜没绕过360webscan(其实是轻松绕过的) ### 详细说明: cmseasy最新版0318 存在一个注入 漏洞文件:/lib/default/archive_act.php 250-251行: ``` function search_action() {//print_r($_SESSION);exit(); if (front::get('ule')) { front::$get['keyword'] = str_replace('-', '%', front::$get['keyword']); front::$get['keyword'] = urldecode(front::$get['keyword']); } if (front::get('keyword') && !front::post('keyword')) front::$post['keyword'] = front::get('keyword'); front::check_type(front::post('keyword'), 'safe'); if (front::post('keyword')) { $this->view->keyword = trim(front::post('keyword')); session::set('keyword', trim(front::post('keyword'))); /* if(isset(front::$get['keyword'])) front::redirect(preg_replace('/keyword=[^&]+/','keyword='.urlencode($this->view->keyword),front::$uri)); else front::redirect(front::$uri.'&keyword='.urlencode($this->view->keyword)); */ } else { $this->view->keyword = session::get('keyword'); } if(preg_match('/union/i',$this->view->keyword) || preg_match('/"/i',$this->view->keyword)...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息