CuuMall免费开源商城系统 越权集合 和cookie泄露用户名密码

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: CuuMall免费开源商城系统 越权集合 ### 详细说明: CuuMall免费开源商城系统 越权可修改对方的 收货地址 个人信息 等等 这里我们举一个例子,修改个人信息 直接看代码: UserInfoAction.class.php:(716-735) ``` public function posteditpro( ) { $uid = $_POST['uid']; $data['shen'] = $_POST['shen']; $data['shi'] = $_POST['shi']; $data['qu'] = $_POST['qu']; $data['sex'] = $_POST['sex']; $data['realname'] = $_POST['realname']; $data['email'] = $_POST['email']; $data['more'] = $_POST['more']; $data['youbian'] = $_POST['youbian']; $data['tel'] = $_POST['tel']; $data['mob'] = $_POST['mob']; $data['qq'] = $_POST['qq']; $data['ww'] = $_POST['ww']; $rej = new Model( "m_per" ); $rej->data( $data )->where( "uid=".$uid )->save( ); $this->assign( "msgTitle", "编辑个人档案成功!" ); $this->success( "编辑个人档案成功!" ); } ``` 我们看看权限判断是靠什么: 还是这个文件(28-35) ``` $co = new Cookie( ); $username = $co->get( c( "GUESTCOOK" )."mall-m-name" ); $password = $co->get( c( "GUESTCOOK" )."mall-m-pass" ); if ( empty( $username ) || empty( $password ) ) { $this->redirect( "home/login" ); exit( ); }...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息