TCCMS SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: TCCMS SQL注入漏洞,可任意用户登陆 ### 详细说明: 前台会员登录处: app/controller/user.class.php: ``` /* 前台会员登陆 */ public function loginIn() { $userObj = M ( 'user' ); $username = trim ( $_POST ['username'] );//注入 $password = trim ( $_POST ['password'] ); $checkError = $this->checkErrorLogin ( $userObj, $username, $password ); if (empty ( $username ) || empty ( $password )) { StringUtil::jsback ( Config::lang ( "USERNAMEORPASSWORDWRONG" ) ); } $isLogin = $userObj->checkUserLogin ( $username, $password ); ``` $username, $password未过滤,进入checkUserLogin,跟进: app/model/userAction.class.php: ``` public function checkUserLogin($username, $password) { $pwd1 = md5(trim($password)); $sql = "select * from " . $this->table . " where username='".$username."' and password='".$pwd1."' and status=1"; $sql = str_replace("#", '', $sql); $sql = str_replace("-", '', $sql); $rt = $this->db->query($sql); $row = mysql_fetch_array($rt); if (!$row) { return false; } else { return $row; } } ``` 直接进入sql语句。 ### 漏洞证明:...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息