phpb2b最新版sql注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: RT ### 详细说明: 在faircontrol.php中: ``` function add_post() { global $charset, $pb_user; if (empty($pb_user)) { die("<img src='".STATICURL."images/check_error.gif'/>".iconv($charset, "UTF-8//IGNORE", L("please_login_first"))); } $the_memberid = $pb_user['pb_userid']; $company_id = ''; if(isset($_POST['do']) && isset($_POST['id'])){ pb_submit_check('do'); if ($this->expo->checkExist($_POST['id']) && !$this->expo->dbstuff->GetOne("SELECT id FROM ".$fair->table_prefix."expos WHERE member_id='".$the_memberid."' AND expo_id='".$_POST['id']."'")) { $sql = "INSERT INTO {$this->expo->table_prefix}expomembers (expo_id,member_id,company_id,created,modified) VALUE (".$_POST['id'].",".$the_memberid.",".$company_id.",".$this->expo->timestamp.",".$this->expo->timestamp.")"; $result = $this->expo->dbstuff->Execute($sql); if (isset($_POST['is_ajax']) && $_POST['is_ajax']) { die("<img src='".STATICURL."images/check_right.gif'/>".iconv($charset, "UTF-8//IGNORE", L("action_successfully"))); }...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息