信游科技页游平台程序又一枚通用型SQL注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 通用性注入 ### 详细说明: 漏洞页面地址 ``` api/payment/checkparams.ashx ``` 源码如下 ``` <%@ WebHandler Language="C#" Class="com.xykj.pay.checkparams" %> using System.Web; using System.Text; using System.Collections.Generic; using System.Linq; using System.Globalization; namespace com.xykj.pay { /// <summary> /// 检查用户信息 /// </summary> public class checkparams : IHttpHandler { public void ProcessRequest(HttpContext context) { var param = context.Request.Params; var r = context.Response; var gid = param["GameId"];//游戏ID var sid = param["ServerId"];//服务器ID //r.Write("200"); //return; try { /*** 判断能否使用该充值方式 *******/ var NotAllow = new string[] { "gpay_epay_pay", "gpay_alipay_pay", "gpay_huanpay_pay", "gpay_shengpay_pay","gpay_eaypay_pay","gpay_huipay_pay", "gpay_xiuxian_pay","gpay_zhigame_pay","gpay_g265_pay","gpay_yeyou35_pay", "gpay_boof_pay"}; var payawy = param["PayAwy"].ToLower(); if (payawy.StartsWith("ty")) payawy = payawy.Substring(2); var payallow = ""; if (payawy.StartsWith("yee"))...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息