shopNC O2O系统任意文件删除漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 齐博齐博快确认,确认了我再送个0day~ shopNC的任意文件删除挺多的,我拿O2O系统来说明问题吧。 ### 详细说明: /circle/control/cut.php 46行 ``` /** * 图片裁剪 * */ public function pic_cutOp(){ import('function.thumb'); if (chksubmit()){ $thumb_width = $_POST['x']; $x1 = $_POST["x1"]; $y1 = $_POST["y1"]; $x2 = $_POST["x2"]; $y2 = $_POST["y2"]; $w = $_POST["w"]; $h = $_POST["h"]; $scale = $thumb_width/$w; $src = str_ireplace(UPLOAD_SITE_URL,BASE_UPLOAD_PATH,$_POST['url']); if (!empty($_POST['filename'])){ $save_file2 = BASE_UPLOAD_PATH.'/'.$_POST['filename']; }else{ $save_file2 = str_replace('_small.','_sm.',$src); } $cropped = resize_thumb($save_file2, $src,$w,$h,$x1,$y1,$scale); @unlink($src); $pathinfo = pathinfo($save_file2); exit($pathinfo['basename']); } $save_file = str_ireplace(UPLOAD_SITE_URL,BASE_UPLOAD_PATH,$_GET['url']); $_GET['x'] = (intval($_GET['x'])>50 && $_GET['x']<400) ? $_GET['x'] : 200; $_GET['y'] = (intval($_GET['y'])>50 && $_GET['y']<400) ? $_GET['y'] : 200; $_GET['resize'] = $_GET['resize'] == '0' ? '0'...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息