DouPHP存储型XSS一枚可打后台管理

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: xss ### 详细说明: 漏洞文件:admin/login.php:68行 ``` $query = $dou->select($dou->table(admin), '*', "user_name = '$_POST[user_name]'"); $user = $dou->fetch_array($query); if (!is_array($user)) { $dou->create_admin_log($_LANG['login_action'] . ": " . $_POST['user_name'] . " ( " . $_LANG['login_user_name_wrong'] . " ) "); $dou->dou_msg($_LANG['login_input_wrong'], 'login.php', 'out'); exit; } elseif (md5($_POST['password']) != $user['password']) { if ($_POST['password']) { $dou->create_admin_log($_LANG['login_action'] . ": " . $_POST['user_name'] . " ( " . $_LANG['login_password_wrong'] . " ) "); } $dou->dou_msg($_LANG['login_input_wrong'], 'login.php', 'out'); exit; } ``` 可以看到当用户名或密码错误时有一次create_admin_log操作: admin/include/action.class.php:210行 ``` function create_admin_log($action) { $create_time = time(); $ip = $this->get_ip(); $sql = "INSERT INTO " . $this->table('admin_log') . " (id, create_time, user_id, action ,ip)" . " VALUES (NULL, '$create_time', '$_SESSION[user_id]',...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息