嘉缘人才系统sql注入#4

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 求20rank ### 详细说明: 看到\frcms\wap\index.php ``` $rid='';$title='我的求职简历';$chinese=$cnstatus=$visitnum=$personinfo=1; $member=$login;$adddate=dtime($fr_time,6);$flag=$regpArray[4]==1?0:1; $rsqls=$rsqlss=''; foreach($rsqlstr as $v){ $v=str_replace('r_','',$v); if(isset($$v)){ $rsqls.="r_$v,"; $rsqlss.="'".cleartags($$v)."',"; } } $rsqls=substr($rsqls,0,-1);$rsqlss=substr($rsqlss,0,-1); $db ->query("INSERT INTO {$cfg['tb_pre']}resume ($rsqls) VALUES($rsqlss)"); $_SESSION["username"]=$login; showwapmsg('注册成功!',"?a=member$w");exit(); } 省略部分代码 if($s=='interviewshow'){ $id=intval($id); $id&&$rss = $db->get_one("select * from {$cfg['tb_pre']}myinterview where i_pmember='$username' and i_id=$id limit 0,1"); $id&&$db->query("update {$cfg['tb_pre']}myinterview set i_read=1 where i_id=$id"); } if($d=='refresh'){ $rid&&$db->query("update {$cfg['tb_pre']}resume set r_adddate=NOW() where r_id='$rid'"); showwapmsg('刷新成功!','0');exit(); }elseif($d=='activate'){ $db ->query("update...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息