HDWIKI最新版Update注入可修改管理员密码(MYSQL进制技巧)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 最新版HDWIKI 5.1 GBK 无视GPC 上首页吧! ### 详细说明: 问题出在\hdwiki\control\user.php下 最新版HDWIKI 5.1 GBK版本 HDWIKI全局过滤,但是面对宽字节注入,就容易出问题了 ``` function doeditprofile(){ if(isset($this->post['submit'])){ $gender = intval($this->post['gender']); $birthday = strtotime($this->post['birthday']); $location = $this->post['location']; $signature = $this->post['signature']; if (WIKI_CHARSET == 'GBK'){ $location = string::hiconv($location); $signature = string::hiconv($signature); } $location = htmlspecialchars($location); $signature = htmlspecialchars(str_replace(array('\n','\r'),'',$signature)); $_ENV['user']->set_profile($gender,$birthday,$location,$signature,$this->user['uid']); }else{ if(0 == $this->user['birthday']){ $birthday = ''; }else{ $birthday=$this->setting['time_offset']*3600+$this->setting['time_diff']*60+$this->user['birthday']; $birthday = date('Y-m-d',$birthday); } $this->view->assign('birthday',$birthday); //$this->view->display('editprofile'); $_ENV['block']->view('editprofile'); }...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息