嘉缘人才系统SQL注入导致任意用户登陆

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 嘉缘人才系统SQL注入导致任意用户登陆 ### 详细说明: 文件member/index.php ``` require('check.php'); if(empty($do)) $do= ''; $titstr="会员中心"; $user_type=_getcookie('user_type');$ut=''; $user_type=='pmember'&&$ut='person'; $user_type=='cmember'&&$ut='company'; $user_type=='smember'&&$ut='school'; $user_type=='tmember'&&$ut='train'; ``` 这里包含了check.php,跟进 文件member/check.php ``` <?php /* [FRCMS] Copyright (c) 2010 Finereason.COM This is NOT a freeware, use is subject to license.txt */ defined('IN_FR') or exit('Access Denied'); !isset($db)&&$db=connectdb(); $goto=urlencode($_SERVER['REQUEST_URI']); $username=_getcookie('user_login'); if($username==''){ $str=''; foreach($_POST as $key => $val){ $str.="&$key=$val"; } $goto=urlencode(joinchar($_SERVER['REQUEST_URI']).substr($str,1)); echo "<script language=JavaScript>{location.href='{$cfg['path']}login.php?goto=$goto';}</script>"; exit(); }else{ $userpass=_getcookie('user_pass'); $rs = $db->get_one("select...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息