yxcms二次注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: yxcms二次注入漏洞 ### 详细说明: ``` /protected/apps/member/controller/photoController.php $data['account']=$this->mesprefix.$this->auth['account']; $data['sort']=$_POST['sort'];//从这里入口 $data['exsort']=empty($_POST['exsort'])?'':implode(',',$_POST['exsort']); $data['title']=in($_POST['title']); $data['keywords']=in($_POST['keywords']); $data['picture']=$_POST['picture']; $data['description']=in($_POST['description']); $data['content']=in($_POST['content']); $data['method']='photo/content'; $data['tpcontent']=in($_POST['tpcontent']); $data['ispass']=0; $data['recmd']=0; $data['hits']=0; $data['norder']=0; $data['addtime']=time(); // if (empty($data['description'])) { // $data['description']=in(substr(deletehtml($_POST['content']), 0, 250)); //自动提取描述 // } // if(empty($data['keywords'])){ // $data['keywords']= $this->getkeyword($data['title'].$data['description']); //自动获取中文关键词 // if(empty($data['keywords'])) $data['keywords']=str_replace(' ',',',$data['description']);//非中文 // } //...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息