phpems 多处sql注射

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: phpems 多处sql注射 ### 详细说明: 百度搜索: title:PHPEMS无纸化模拟考试系统 [<img src="https://images.seebug.org/upload/201504/071929425a63f822f5851f3d4924460d12ed23a5.png" alt="3.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/071929425a63f822f5851f3d4924460d12ed23a5.png) ev.cls.php: ``` public function getClientIp() { if(!isset($this->e['ip'])) { if (getenv("HTTP_CLIENT_IP") && strcasecmp(getenv("HTTP_CLIENT_IP"), "unknown")) $ip = getenv("HTTP_CLIENT_IP"); else if (getenv("HTTP_X_FORWARDED_FOR") && strcasecmp(getenv("HTTP_X_FORWARDED_FOR"), "unknown")) $ip = getenv("HTTP_X_FORWARDED_FOR"); else if (getenv("REMOTE_ADDR") && strcasecmp(getenv("REMOTE_ADDR"), "unknown")) $ip = getenv("REMOTE_ADDR"); else if (isset($_SERVER['REMOTE_ADDR']) && $_SERVER['REMOTE_ADDR'] && strcasecmp($_SERVER['REMOTE_ADDR'], "unknown")) $ip = $_SERVER['REMOTE_ADDR']; else $ip = "unknown"; $this->e['ip'] = $ip; } return $this->e['ip']; } ``` 搜索: getClientIp [<img...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息