PHPYun v3.2...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

<ul><li>/ask/model/index.class.php</li></ul><pre class="">$i_ids=$is_set['ids'].','.$_POST['id']; $n_id=$this-&gt;obj-&gt;update_once("attention",array("ids"=&gt;$i_ids),array("id"=&gt;$is_set['id'])); if($n_id) { $data['uid']=$this-&gt;uid; $data['content']=$content; $data['ctime']=time(); $this-&gt;obj-&gt;insert_into("friend_state",$data); echo '1'; }else{ echo '0'; } $i_ids拼接用戶POST的id。 function attenquestion_action() { if($this-&gt;uid=='') { $this-&gt;obj-&gt;ACT_msg($_SERVER['HTTP_REFERER'],"请先登录!"); } $this-&gt;public_action(); $ids=$this-&gt;obj-&gt;DB_select_once("attention","`uid`='".$this-&gt;uid."' and `type`='1'","`ids`"); $ids=rtrim($ids['ids'],','); $pageurl=$this-&gt;aurl(array("url"=&gt;"c:".$_GET['c'].",page:{{page}}")); $question=$this-&gt;get_page("question","`id` in (".$ids.") order by `add_time` desc",$pageurl,"10"); </pre><p>将ids取出,拼接进入SQL语句导致二次注入。当用户提交:</p><pre class="">type=1&amp;id=2) and 1=2 union select...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息