TIPASK问答系统SQL注入二(有多个大型互联网企业案例)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 审核真给力,刚提交就通过了 ,赞啊!!!! ### 详细说明: 部分案例: [<img src="https://images.seebug.org/upload/201412/131743219ef90cabffb2d717fd9b455e771b7176.jpg" alt="0.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/131743219ef90cabffb2d717fd9b455e771b7176.jpg) 经分析下列文件存在注入 /control/message.php 代码如下 ``` function onremovedialog() { if($this->post['message_author']){ $authors = $this->post['message_author']; $_ENV['message']->remove_by_author($authors); $this->message("对话删除成功!", get_url_source()); } } ``` 跟进remove_by_author函数 ``` function remove_by_author($authors) { foreach ($authors as $fromuid) { $this->db->query("DELETE FROM " . DB_TABLEPRE . "message WHERE fromuid<>touid AND ((fromuid=$fromuid AND touid=" . $this->base->user['uid'] . ") AND status=1)"); $this->db->query("DELETE FROM " . DB_TABLEPRE . "message WHERE fromuid<>touid AND ((fromuid=" . $this->base->user['uid'] . " AND touid=" . $fromuid . ") AND status=2"); $this->db->query("UPDATE " ....

0%
暂无可用Exp或PoC
当前有0条受影响产品信息