PHPshe sql注入漏洞2

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: PHPshe 注入漏洞2 ### 详细说明: ``` <?php pe_lead('hook/product.hook.php'); switch ($act) { //#####################@ 商品咨询 @#####################// case 'askadd': if (isset($_p_pesubmit)) { $info['product_id'] = intval($_g_id); $info['ask_text'] = pe_texthtml(pe_dbhold($_p_ask_text)); $info['ask_atime'] = time(); $info['user_id'] = $_s_user_id; $info['user_name'] = $_s_user_name; $info['user_ip'] = pe_ip();//ip获取直接注入 if ($db->pe_insert('ask', $info)) { product_num('asknum', $info['product_id']); $result = true; $info['ask_atime'] = pe_date($info['ask_atime']); $info['ask_text'] = htmlspecialchars($_p_ask_text); $html = <<<html <ul> <li class="fl"> function pe_ip() { if (isset($_SERVER)){ if (isset($_SERVER["HTTP_X_FORWARDED_FOR"])){ $realip = $_SERVER["HTTP_X_FORWARDED_FOR"]; } else if (isset($_SERVER["HTTP_CLIENT_IP"])) { $realip = $_SERVER["HTTP_CLIENT_IP"]; } else { $realip = $_SERVER["REMOTE_ADDR"]; } } else { if (getenv("HTTP_X_FORWARDED_FOR")){ $realip =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息