phpyun v3.2 (20141222) 三处注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 20141222 ### 详细说明: 第一处在 api/alipay/alipayto.php 现在的少了以前的验证。 ``` error_reporting(0); require_once("alipay_config.php"); require_once("class/alipay_service.php"); require_once(dirname(dirname(dirname(__FILE__)))."/data/db.config.php"); require_once(dirname(dirname(dirname(__FILE__)))."/plus/config.php"); require_once(dirname(dirname(dirname(__FILE__)))."/include/mysql.class.php"); //看这里 主要是没包含db.safety.php进来 导致了这里面的_POST啥的不转义 不过滤 $db = new mysql($db_config['dbhost'], $db_config['dbuser'], $db_config['dbpass'], $db_config['dbname'], ALL_PS, $db_config['charset']); if(!is_numeric($_POST['dingdan'])){die;} $_COOKIE['uid']=(int)$_COOKIE['uid']; $_POST['is_invoice']=(int)$_POST['is_invoice']; $_POST['balance']=(int)$_POST['balance']; $member_sql=$db->query("SELECT * FROM `".$db_config["def"]."member` WHERE `uid`='".$_COOKIE['uid']."' limit 1");//把自己的账户信息查询出来 $member=mysql_fetch_array($member_sql); if($member['username'] != $_COOKIE['username'] || $member['usertype'] !=...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息