FengCms 过滤不言导致sql注入,可爆管理用户名密码

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 这个小的cms刚问世,我就测了下。感觉还是不错。但是百密终有一疏。注入啊…… ### 详细说明: ``` /app/model/moduleModel.php 文件中 search函数是前台做搜索用的。具体看代码 public function search($arrays,$field="",$num="20"){ //var_dump($arrays); //var_dump($field); //die; if($arrays['project']){ $sql='select * from `'.DB_PREFIX.$arrays['project'].'` where title like "%'.$arrays['tags'].'%" or tags like "%'.$arrays['tags'].'%"'; //var_dump($sql); //die; return arraypage(D($this->d_name)->excsql($sql.' order by id desc'),$num); }else{ $arr=D($this->d_name)->field("project")->where("type=1&&search=1")->getall(); if(count($arr)>1)$union="union"; foreach($arr as $k => $v){ if($this->attrib($v['project'],'tags')){ $array[]='select '.$this->fieldhandle($field).'id,title,html,time from `'.DB_PREFIX.$v['project'].'` where title like "%'.$arrays['tags'].'%" or tags like "%'.$arrays['tags'].'%" and status=1'; }else{ $array[]='select '.$this->fieldhandle($field).'id,title,html,time from `'.DB_PREFIX.$v['project'].'` where title like...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息