PHPB2B某处sql注入#5

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: PHPB2B某处sql注入#5 ### 详细说明: 官网下载的最新版本 PHPB2B某处sql注入 virtual-office/favor.php 25-45行 ``` if(isset($_POST['do']) && isset($_POST['id'])){ //check limit $type_id = 1; $f_limit = $pdb->GetOne($sql = "SELECT count(id) FROM {$tb_prefix}favorites WHERE type_id='".$type_id."' AND member_id=".$the_memberid); if ($trade_model->checkExist($_POST['id'])) { if ($g['max_favorite']==0 or $g['max_favorite']>$f_limit) { $sql = "INSERT INTO {$tb_prefix}favorites (target_id,member_id,type_id,created,modified) VALUE (".$_POST['id'].",".$the_memberid.",".$type_id.",".$time_stamp.",".$time_stamp.")"; $result = $pdb->Execute($sql); }else{ flash("post_max"); } }else{ flash("data_not_exists"); } if($result){ echo "<script language='javascript'>window.close();</script>"; exit; }else { flash("been_favorited", '', 0); } } ``` ``` $sql = "INSERT INTO {$tb_prefix}favorites (target_id,member_id,type_id,created,modified) VALUE...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息