大汉JCMS 注入漏洞3

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 大汉JCMS 注入漏洞3 ### 详细说明: short_message/que_sendmsg.jsp ``` String strTitle = ""; /*检索关键字*/ String groupname = ""; String id = Convert.getParameter(request, "loginid", "a");//获取参数 String boxtype = Convert.getParameter(request, "boxtype", "a"); strTitle += groupname; // 获取表单提交变量(条件参数) String strQueKeyWords = "";//关键字 String strQueKeyWords1 = "";//高级检索关键字 String strQueScope = "";//范围 String strStartDate = "";//开始日期 String strEndDate = "";//结束日期 strQueKeyWords = Convert.getParameter(request, "que_keywords"); strQueKeyWords1 = Convert.getParameter(request, "que_keywords1"); strQueScope = Convert.getParameter(request, "que_scope"); strStartDate = Convert.getParameter(request, "que_startdate"); strEndDate = Convert.getParameter(request, "que_enddate"); strQueKeyWords = (strQueKeyWords1.length() > 0) ? strQueKeyWords1 : strQueKeyWords;//高级检索的关键字优先 //组织时间条件 String strDateCond = ""; if (!"".equals(strStartDate) && !"".equals(strEndDate)) { strDateCond += " AND a.dt_sendtime >= '" +...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息