UChome 注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: UChome 注入漏洞 ### 详细说明: ``` source/cp_clbum.php } elseif($_GET['op'] == 'editpic') { $managealbum = checkperm('managealbum'); include_once(S_ROOT.'./source/function_bbcode.php'); if($albumid > 0) { $query = $_SGLOBAL['db']->query("SELECT * FROM ".tname('album')." WHERE albumid='$albumid'"); if(!$album = $_SGLOBAL['db']->fetch_array($query)) { showmessage('no_privilege'); } if($album['uid'] != $_SGLOBAL['supe_uid'] && !$managealbum) { showmessage('no_privilege'); } } if(submitcheck('editpicsubmit')) { if($_GET['subop'] == 'delete') { //删除 $updates = $deleteids = array(); foreach ($_POST['title'] as $picid => $value) { if(empty($_POST['ids'][$picid])) { $title = getstr($value, 150, 1, 1, 1); $wherearr = array('picid'=>$picid); if(!$managealbum) $wherearr['uid'] = $_SGLOBAL['supe_uid'];//自己 updatetable('pic', array('title'=>$title), $wherearr); } else { $deleteids[$picid] = $picid; } } if($deleteids) { include_once(S_ROOT.'./source/function_delete.php');...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息