Iwebshop最新版注入又一枚

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: Iwebshop最新版注入又一枚 ### 详细说明: 看到wooyun上有人提了几个iweshop(2014-11-18更新)的漏洞( [WooYun: iWebShop开源电子商务系统SQL注入漏洞](http://www.wooyun.org/bugs/wooyun-2014-087202) ),去官网看了看,在2014-12-16 已更新到了 iwebshop2.9.14121000,下下来研究研究,希望不要重复。 注入一枚:POST /index.php?controller=seller&action=order_list POST参数中的search作为一个数组传入,search的KEY and VALUE 都过滤不完全,注入成功,文件在/controllers/seller.php的order_list()方法中 看看代码/controllers/seller.php ``` public function order_list(){ //搜索条件 $seller_id = $this->seller['seller_id']; $search = IFilter::act(IReq::get('search')); $page = IReq::get('page') ? IFilter::act(IReq::get('page'),'int') : 1; //检索条件 list($join,$where) = order_class::getSellerSearchCondition($search); $where .= " and go.seller_id=".$seller_id; //拼接sql $orderHandle = new IQuery('order_goods as og'); $orderHandle->order = "o.id desc"; $orderHandle->fields = "o.*"; $orderHandle->page = $page; $orderHandle->join = $join; $orderHandle->where = $where; $this->search = $search; $this->orderHandle = $orderHandle;...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息