PHPSHE某处SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: ~~~ ### 详细说明: 文件order.php ``` //#####################@ 订单增加 @#####################// case 'add': $cart_info = cart_info(unserialize($_c_cart_list)); $info_list = $cart_info['list']; $money = $cart_info['money']; ``` $cart_info = cart_info(unserialize($_c_cart_list)); 这里的$_c_cart_list就是Cookie中的cart_list 反序列化后进入cart_info函数。 跟进cart_info函数 ``` //购物车商品列表和价格 function cart_info($_c_cart_list=array()) { global $db; if (pe_login('user')) { $sql = "select a.`product_num`, b.`product_id`, b.`product_name`, b.`product_logo`, b.`product_smoney`, b.`product_wlmoney`, b.`product_num` as `product_maxnum` from `".dbpre."cart` a, `".dbpre."product` b where a.`product_id` = b.`product_id` and a.`user_id` = '{$_SESSION['user_id']}'"; $info_list = $db->sql_selectall($sql); } else { if (is_array($_c_cart_list)) { foreach ($_c_cart_list as $k => $v) { $product_rows = $db->pe_select('product', array('product_id'=>$k), '`product_name`, `product_logo`, `product_smoney`, `product_wlmoney`,...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息