Ecmall 前台任意文件删除

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 删除lock之后可以重装系统 然后连接上自己搭建的mysql环境 重装后 。。。。然后就各种操作。 20140618 ### 详细说明: 在app/my_goods.app.php中 ``` function drop_image() { $id = empty($_GET['id']) ? 0 : intval($_GET['id']); $uploadedfile = $this->_uploadedfile_mod->get(array( 'conditions' => "f.file_id = '$id' AND f.store_id = '{$this->_store_id}'", 'join' => 'belongs_to_goodsimage', 'fields' => 'goods_image.image_url, goods_image.thumbnail, goods_image.image_id, f.file_id', )); if ($uploadedfile) { $this->_uploadedfile_mod->drop($id); if ($this->_image_mod->drop($uploadedfile['image_id'])) { // 删除文件 if (file_exists(ROOT_PATH . '/' . $uploadedfile['image_url'])) { @unlink(ROOT_PATH . '/' . $uploadedfile['image_url']); } if (file_exists(ROOT_PATH . '/' . $uploadedfile['thumbnail'])) { @unlink(ROOT_PATH . '/' . $uploadedfile['thumbnail']); } ``` ``` $uploadedfile = $this->_uploadedfile_mod->get(array( 'conditions' => "f.file_id = '$id' AND f.store_id = '{$this->_store_id}'", 'join' => 'belongs_to_goodsimage', 'fields' =>...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息