CuuMall最新版sql注入(可买任意商品,任意刷钱,想干啥就干啥)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: CuuMall免费网上商城系统基于企业级MVC技术架构,安全、稳定,可保证同时在线人数达10000人左右,能适应不同领域的公司企业,文件缓存机制、数据库缓存机制,保证系统稳定运行,多种功能以满足不同客户网上开店的需求。 ### 详细说明: ``` // 获取某个Cookie值 static function get($name) { $value = $_COOKIE[C('COOKIE_PREFIX').$name]; $value = unserialize(base64_decode($value)); return $value; } ``` 获取cookie操作,只是做了一次base解码。 再来看cookie的账号登陆: ``` $co = new Cookie( ); $username = ($co->get( "GUESTCOOK" )."mall-m-name" ); $password = ($co->get( "GUESTCOOK" )."mall-m-pass" ); if ( empty( $username ) || empty( $password ) ) { $this->assign( "waitSecond", 3 ); $this->assign( "msgTitle", "请登录后购买" ); $this->assign( "jumpUrl", "__APP__/home/login" ); $this->error( "请登录后购买" ); exit( ); } $m_member = new Model( "m_member" ); $d_m_member = $m_member->where( "username='".$username."'" )->find( ); if ( empty( $d_m_member ) ) { $this->assign( "waitSecond", 3 ); $this->assign( "msgTitle", "请登录后购买" ); $this->assign( "jumpUrl", "__APP__/home/login" ); $this->error( "请登录后购买" ); exit( ); } if ( $password !=...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息