Discuz可CSRF脱裤

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: Discuz CSRF脱裤! 广告位 承接代码审计 codescan.cn codescan#yeah.net ### 详细说明: ``` admin_db.php if(!$backupdir) { $backupdir = random(6); @mkdir('./data/backup_'.$backupdir, 0777);//文件夹名是六位随机数 C::t('common_setting')->update('backupdir',$backupdir);/ } else {//这边也没有做fromhash的验证 估计是方便AJAX请求~ DB::query('SET SQL_QUOTE_SHOW_CREATE=0', 'SILENT'); if(!$_GET['filename'] || !preg_match('/^[\w\_]+$/', $_GET['filename'])) { cpmsg('database_export_filename_invalid', '', 'error'); } $time = dgmdate(TIMESTAMP); if($_GET['type'] == 'discuz' || $_GET['type'] == 'discuz_uc') { $tables = arraykeys2(fetchtablelist($tablepre), 'Name'); } elseif($_GET['type'] == 'custom') { $tables = array(); if(empty($_GET['setup'])) { $tables = C::t('common_setting')->fetch('custombackup', true); } else { C::t('common_setting')->update('custombackup', empty($_GET['customtables'])? '' : $_GET['customtables']); $tables = & $_GET['customtables']; } if( !is_array($tables) || empty($tables)) {...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息