嘉缘人才系统两处sql注入打包(直接出数据)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 最新版 20150126 ### 详细说明: 看到\frcms\member\company_myexpert.php ``` elseif($do=='myexpert'){ if($Glimit[1]<0){showmsg('您所在的会员组您无权使用人才库!',"-1",0,2000);exit();} require_once(FR_ROOT.'/inc/paylog.inc.php'); $checksnum=count(explode(',',$checks)); //var_dump($uinfo['m_name']); //exit; if($Glimit[1]&&$uinfo['limit'][11]<$checksnum){showmsg('您的人才库可用数量不足,请返回重新选择!',"-1",0,2000);exit();} if($checks!=''){ $sql="select r_id,r_name,r_sex,r_birth,r_edu,r_member from {$cfg['tb_pre']}resume where r_id in ($checks) order by r_adddate desc limit 0,$checksnum"; $query=$db->query($sql); $i=0; while($row=$db->fetch_array($query)){ $rsd = $db->get_one("select * from {$cfg['tb_pre']}myexpert where m_pmember='$row[r_member]' and m_cmember='$username' and m_rid=$row[r_id] limit 0,1"); if(!$rsd){ $db ->query("INSERT INTO {$cfg['tb_pre']}myexpert (m_rid,m_name,m_sex,m_birth,m_edu,m_cmember,m_pmember,m_adddate,m_exp)...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息