PHPEMS一处SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: PHPEMS一处SQL注入漏洞 ### 详细说明: 5.phpems某处SQL注入漏洞 存在注入漏洞代码位于/app/exam/app.php的函数favor()中 具体在 default: $page = $this->ev->get('page'); $type = $this->ev->get('type'); $search = $this->ev->get('search'); $tmp = $this->section->getKnowsListByArgs(array("knowssectionid = '{$search['sectionid']}'","knowsstatus = 1")); if($search['sectionid'] && !$search['knowsid']) { $search['knowsid'] = ''; if(is_array($tmp)) { foreach($tmp as $p) $search['knowsid'] .= $p['knowsid'].","; } } $search['knowsid'] = trim($search['knowsid']," ,"); $page = $page > 0?$page:1; $args = array("favorsubjectid = '{$this->data['currentbasic']['basicsubjectid']}'","favoruserid = '{$this->_user['sessionuserid']}'"); if($search['knowsid'])$args[] = "quest2knows.qkknowsid IN ({$search['knowsid']})";// SQL注入漏洞 if($type) { if($search['questype'])$args[] = "questionrows.qrtype = '{$search['questype']}'"; $favors = $this->favor->getFavorListByUserid($page,20,$args,1); } 这几行上 if($search['knowsid'])$args[] =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息