LebiShop系统sql注入三(两处注入)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: LebiShop商城系统最新版SQL注入二 四处 官方demo演示 ### 详细说明: 注入一 ``` http://demo.lebi.cn/onlinepay/tenpayJSDZ/payNotifyUrl.aspx ``` 源码如下 ``` protected void Page_Load(object sender, EventArgs e) { string where = base.Request["out_trade_no"]; //没处理 Lebi_Order model = B_Lebi_Order.GetModel(where); //跟进 if (model == null) { base.Response.Write("系统错误"); base.Response.End(); } else { TenpayUtil util = new TenpayUtil(model); ResponseHandler handler = new ResponseHandler(this.Context); .... public Lebi_Order_Log GetModel(string strWhere) { if (strWhere.IndexOf("lbsql{") > 0) { SQLPara para = new SQLPara(strWhere, "", ""); return this.GetModel(para); } StringBuilder builder = new StringBuilder(); builder.Append("select top 1 * from [Lebi_Order_Log] "); builder.Append(" where " + strWhere); //strWhere 没处理存在注入 Lebi_Order_Log log = new Lebi_Order_Log(); DataSet set = SqlUtils.SqlUtilsInstance.TextExecuteDataset(builder.ToString()); if (set.Tables[0].Rows.Count <= 0) { return null; } if...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息