TinyRise 最新版sql注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: TinyRise 最新版sql注入 ### 详细说明: simple.php: ``` $order_type = 2; }else if($type=="bundbuy"){//捆绑销售处理 $product_ids = implode(',', $product_id); $num = Filter::int($buy_num[0]); $model = new Model("bundling"); $bund = $model->where("id=$id")->find(); if($bund){ $goods_id = $bund['goods_id']; $products = $model->table("goods as go")->join("left join products as pr on pr.goods_id=go.id")->where("pr.id in ($product_ids)")->fields("*,pr.id as product_id,pr.spec")->group("go.id")->findAll(); $order_products = $this->packBundbuyProducts($products,$num); } ``` 这个地方存在sql注入 首先这 $product_ids = implode(',', $product_id); 然后: ``` $products = $model->table("goods as go")->join("left join products as pr on pr.goods_id=go.id")->where("pr.id in ($product_ids)")->fields("*,pr.id as product_id,pr.spec")->group("go.id")->findAll(); $order_products = $this->packBundbuyProducts($products,$num); ``` 这是 进入到sql注入 这里貌似只能进行盲注 访问url: http://localhost/tinyshopv1.1/index.php?con=simple&act=order_act...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息