DouPHP可CSRF脱裤

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: DouPHP可CSRF脱裤。 ### 详细说明: 在www\admin\backup.php: ``` if ($rec == 'backup') { $fileid = isset($_REQUEST['fileid']) ? $_REQUEST['fileid'] : 1; $tables = $_REQUEST['tables']; $vol_size = $_REQUEST['vol_size']; $totalsize = $_REQUEST['totalsize']; $file_name = $_REQUEST['file_name']; //1、用户输入的文件作为备份文件名 // 判断备份文件名是否规范 if (!$check->is_backup_file($file_name . '.sql')) //2、is_backup_file 仅检查是否是字母数字开头、.sql结尾 $dou->dou_msg($_LANG['backup_file_name_not_valid'], 'backup.php'); if ($fileid == 1 && $tables) { if (!isset($tables) || !is_array($tables)) { $dou->dou_msg($_LANG['backup_no_select'], 'backup.php'); } $cache_file = ROOT_PATH . 'data/backup/tables.php'; $content = "<?php\r\n"; $content .= "\$data = " . var_export($tables, true) . ";\r\n"; $content .= "?>"; file_put_contents($cache_file, $content, LOCK_EX); } else { include ROOT_PATH . 'data/backup/tables.php'; $tables = $data; if (!$tables) { $dou->dou_msg($_LANG['backup_no_select'], 'backup.php'); } } if ($dou->version() >...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息