Mcms 无视全局转义SQL注入一枚

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 过滤不严。 ### 详细说明: 虽然有全局转义 但是在plugins/gov.order/order.php中 ``` function m__save_order(){ global $dbm; //判断登陆 if(!isset($_SESSION['uid']) || !isset($_SESSION['uname'])) die('{"code":"100","msg":"你还没有登陆,请登入后再购买"}'); $info_id = $_POST['info_id']; $info_title = urldecode($_POST['info_title']); $price = isset($_POST['price'])?$_POST['price']:0; $number = isset($_POST['number'])?$_POST['number']:0; if(!is_numeric($price)) die('{"code":"100","msg":"价格必须是数字"}'); if(!is_numeric($number)) die('{"code":"100","msg":"数量必须是数字"}'); if(intval($price)<=0) die('{"code":"120","msg":"购买数量不能少于1"}'); if(strlen($_POST['rev_user'])<2) die('{"code":"100","msg":"收货人姓名必须填写"}'); if(strlen($_POST['rev_addr'])<6) die('{"code":"100","msg":"收货人地址必须填写"}'); if(strlen($_POST['rev_phone'])<8) die('{"code":"100","msg":"收货人手机必须填写"}'); $params['order_content'] = ''; $params['pay_total'] = 0; $params['order_content'] .= $price."元 x ".$number.""; $params['pay_total'] += $number*$price; //订单数据 $params['uid'] =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息