骑士CMS某接口SQL注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 骑士CMS某接口SQL注入,官网测试。 ### 详细说明: 翻了翻代码,看到有这么一段: user/company/company_jobs.php: ``` elseif ($act=='jobs_perform') { global $_CFG; $yid =!empty($_POST['y_id'])?$_POST['y_id']:$_GET['y_id']; $jobs_num=count($yid); if (empty($yid)) { showmsg("ÄãûÓÐÑ¡Ôñְλ£¡",1); } $refresh=!empty($_POST['refresh'])?$_POST['refresh']:$_GET['refresh']; $delete=!empty($_POST['delete'])?$_POST['delete']:$_GET['delete']; if ($refresh) { if($jobs_num==1){ if(is_array($yid)){ $yid = $yid[0]; } $jobs_info = $db->getone("select * from ".table('jobs')." where id=".$yid); if(empty($jobs_info)){ $jobs_info = $db->getone("select * from ".table('jobs_tmp')." where id=".$yid); } if($jobs_info['deadline']<time()){ showmsg("žÃְλÒѵœÆÚ£¬ÇëÏÈÑÓÆÚ£¡",1); } } ``` 下面的GET/POST参数没有check, ``` $yid =!empty($_POST['y_id'])?$_POST['y_id']:$_GET['y_id'] ``` 然后就带入了SQL: ``` $jobs_info = $db->getone("select * from ".table('jobs')." where id=".$yid); ``` 这不是可以注入么?官网试试,果然是这样: ```...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息