ECSHOP后台低权限sql注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: ECSHOP后台低权限sql注入一枚 ### 详细说明: 普通发货员在登陆之后只需要一个订单列表的权限(也就是低权限管理员即可)就可以注入得到超管权限 如有文件权限还可以getshell 问题出在/admin/order.php中 ``` if (!empty($_COOKIE['ECSCP']['lastfilter'])) { $filter = unserialize(urldecode($_COOKIE['ECSCP']['lastfilter']));///// //这里urldecode了$_COOKIE['ECSCP']['lastfilter'],可怜的GPC~~唉…… if (!empty($filter['composite_status'])) { $where = ''; //综合状态 switch($filter['composite_status']) { case CS_AWAIT_PAY : $where .= order_query_sql('await_pay'); break; case CS_AWAIT_SHIP : $where .= order_query_sql('await_ship'); break; case CS_FINISHED : $where .= order_query_sql('finished'); break; default: if ($filter['composite_status'] != -1) { $where .= " AND o.order_status = '$filter[composite_status]' "; //这里将composite_status直接带入了sql } } } ``` ------详细过程------------------------------------------ 1.点击订单列表: [<img src="https://images.seebug.org/upload/201312/191409366c07d84ec02a0b9b124ddd77fe9f160d.jpg" alt="1.jpg" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息