大米CMS某处SQL盲注2

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 大米CMS某处SQL盲注第二发,可直接拖库 ### 详细说明: 文件/Web/Lib/Action/ApiAction.class.php ``` //万能获取数据接口 function ajax_arclist(){ $prefix = !empty($_REQUEST['prefix'])?(bool)$_REQUEST['prefix']:true; //表过滤防止泄露信息,只允许的表 if(!in_array($_REQUEST['model'],array('article','type','ad','label','link'))){exit();} if(!empty($_REQUEST['model'])){ if($prefix == true){ $model = C('DB_PREFIX').$_REQUEST['model']; } else{ $model =$_REQUEST['model']; } }else{ $model = C('DB_PREFIX').'article'; } $order =!empty($_REQUEST['order'])?$_REQUEST['order']:''; $num =!empty($_REQUEST['num'])?$_REQUEST['num']:''; $where =!empty($_REQUEST['where'])?urldecode($_REQUEST['where']):''; //使where支持 条件判断,添加不等于的判断 $page=false; echo $_REQUEST['page']; if(!empty($_REQUEST['page'])) $page=(bool)$_REQUEST['page']; $pagesize =!empty($_REQUEST['pagesize'])?$_REQUEST['pagesize']:'10'; //$query =!empty($_REQUEST['sql'])?$_REQUEST['sql']:'';//太危险不用 $field =!empty($_REQUEST['field'])?$_REQUEST['field']:''; $m=new Model($model,"",false);...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息