深澜软件漏洞SrunDisk注入漏洞三

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: RT ### 详细说明: 文件:\userinfo.php ``` include_once("kernel/eidolon.class.php"); $eidolon=new Eidolon("templets/userinfo.html"); include_once("kernel/member.class.php"); $member=new Member(); if($res=$member->searchByName($_GET["username"],0,"")) { foreach($res as $v) { extract($v,EXTR_OVERWRITE); } } $eidolon->parseBlock("_main"); $eidolon->showBlock("_main"); ``` ``` $res=$member->searchByName($_GET["username"],0,"")) ``` 传递到searchByName中,然后跟中member.class.php文件中 ``` function searchByName($key,$mo,$order) { $where=""; $where.=($this->role_id>0)?" AND role_id=".($this->role_id - 1):""; $where.=($this->mg_id>0)? " AND members.mg_id=".$this->mg_id:""; if($order!="member_name" && $order !="member_reg_date" && $order != "member_log_date" && $order != "role_id") { $order="member_id"; } if($key=="") { $sql= "SELECT * FROM members LEFT JOIN member_groups ON members.mg_id=member_groups.mg_id WHERE 1=1 ".$where." ORDER BY '".$order."' DESC LIMIT ".$this->getLimit();; } else if($mo==1)...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息