PHPSHE电商程序SQL注入4

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: PHPSHE电商程序SQL注入5 ### 详细说明: 在商品列表处,有特殊参数没有过滤,导致SQL注入。 在/module/index/product.php文件。 来看看商品列表代码: ``` //#####################@ 商品列表 @#####################// case 'list': $category_id = intval($id); $info = $db->pe_select('category', array('category_id'=>$category_id)); //搜索 $sqlwhere = " and `product_state` = 1"; pe_lead('hook/category.hook.php'); if ($category_id) { $sqlwhere .= is_array($category_cidarr = category_cidarr($category_id)) ? " and `category_id` in('".implode("','", $category_cidarr)."')" : " and `category_id` = '{$category_id}'"; } $_g_keyword && $sqlwhere .= " and `product_name` like '%".pe_dbhold($_g_keyword)."%'"; if ($_g_orderby) { $orderby = explode('_', $_g_orderby);//将参数分割 $sqlwhere .= " order by `product_{$orderby[0]}` {$orderby[1]}";//将分割后的参数直接带入 } else { $sqlwhere .= " order by `product_id` desc"; } $info_list = $db->pe_selectall('product', $sqlwhere, '*', array(16, $_g_page));//进入sql语句 //热卖排行 $product_hotlist = product_hotlist(); //当前路径 $nowpath =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息