TIPASK问答系统SQL注入三(有多个大型互联网企业案例)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: TIPASK问答系统SQL注入三(影响天极网、戴尔中国、WPS office、小米等网站) ### 详细说明: 部分案例: [<img src="https://images.seebug.org/upload/201412/131743219ef90cabffb2d717fd9b455e771b7176.jpg" alt="0.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/131743219ef90cabffb2d717fd9b455e771b7176.jpg) 通过源代码发现/control/gift.php存在注入,部分代码如下 ``` function onadd() { if(isset($this->post['realname'])) { $realname = $this->post['realname']; $email = $this->post['email']; $phone = $this->post['phone']; $addr = $this->post['addr']; $postcode = $this->post['postcode']; $qq = $this->post['qq']; $notes = $this->post['notes']; $gid = $this->post['gid']; $param = array(); if(''==$realname || ''==$email || ''==$phone||''==$addr||''==$postcode) { $this->message("为了准确联系到您,真实姓名、邮箱、联系地址(邮编)、电话不能为空!",'gift/default'); } if (!preg_match("/^[a-z'0-9]+([._-][a-z'0-9]+)*@([a-z0-9]+([._-][a-z0-9]+))+$/",$email)) { $this->message("邮件地址不合法!",'gift/default'); } if(($this->user['email'] != $email) &&...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息