shop7z 商品列表处搜索型注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: productlist.asp文件注入 ### 详细说明: productlist.asp文件124-146 ``` <% sql_condition=" where updown='1' " if kind<>"" then sql_condition = sql_condition & " and ( kind like '"&kind&"%' or kind2 like '"&kind&"%' ) " end if if cx<>"" then sql_condition = sql_condition & " and good='1' " end if if hot<>"" then sql_condition = sql_condition & " and hot='1' " end if if searchkind<>"" then sql_condition = sql_condition & " and kind like '"&searchkind&"%' " end if if keyword<>"" then sql_condition = sql_condition & " and (model like '%"&keyword&"%' or productname like '%"&keyword&"%' or pipai like '%"&keyword&"%') " end if order_name=" pkid desc " sql="select pkid,model,productname,smallpicpath,price1,price"&session("customkind")&",kindname,pipai,addtime from view_product "&sql_condition&" order by "&order_name ``` ### 漏洞证明: [<img src="https://images.seebug.org/upload/201409/15184304d50c06974772cb9eecf1a3eca1fb239d.jpg" alt="produce.jpg" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息