74cms最新版 二次注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: ### 详细说明: 74cms 20141128最新版 漏洞文件:/wap/plus/wap_ajax.php 610-654行: ``` elseif ($act == 'invited_add') { $smarty->cache = false; $resume=resume_one($_POST["resume_id"]); $jobs=jobs_one($_POST["jobs_id"]); if($_SESSION['utype']!=1){ exit("企业会员请登录后邀请面试"); } if (check_interview($_POST["resume_id"],$_POST["jobs_id"],$_SESSION['uid'])) { exit("repeat"); } $addarr['resume_id']=$resume['id']; $addarr['resume_addtime']=$resume['addtime']; if ($resume['display_name']=="2") { $addarr['resume_name']="N".str_pad($resume['id'],7,"0",STR_PAD_LEFT); } elseif ($resume['display_name']=="3") { $addarr['resume_name']=cut_str($resume['fullname'],1,0,"**"); } else { $addarr['resume_name']=$resume['fullname']; } $addarr['resume_uid']=$resume['uid']; $addarr['company_id']=$jobs['company_id']; $addarr['company_addtime']=$jobs['company_addtime']; $addarr['company_name']=$jobs['companyname']; $addarr['company_uid']=$_SESSION['uid']; $addarr['jobs_id']=$jobs['id'];...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息