大米CMS最新版SQL盲注4绕过防御

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 大米CMS最新版4.7,某处绕过防御SQL盲注 ### 详细说明: 大米CMS最新版4.7,2014-12-12更新 文件/Web/Lib/Action/MemberAction.class.php: ``` //创建帐号 function qqcreate(){ $data = array_map('strval',$_POST); $data = array_map('remove_xss',$data); if($data['realname']=='' || $data['qid']==''){$this->error('参数错误!');exit();} $t = M('member')->where("username='".$data['realname']."'")->find(); if(!$t){ $data['username'] = $data['realname']; }else{ $data['username'] = (string)time(); } $data['userpwd'] = md5(time().rand(0,9999)); $uid = M('member')->add($data); $_SESSION['dami_uid'] = $uid; $_SESSION['dami_username'] = $data['username']; $_SESSION['dami_usericon'] = $data['icon']; if(!empty($_REQUEST['lasturl'])){ $this->assign('jumpUrl',urldecode(htmlspecialchars($_REQUEST['lasturl']))); }else{ $this->assign('jumpUrl',U('Member/main')); } $this->success('绑定成功,正在登陆~'); } ``` 注意这里: ``` $t = M('member')->where("username='".$data['realname']."'")->find(); ``` $data =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息