phpyun SQL注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 处理不当导致注入,绕过waf ### 详细说明: 在/model/qqconnect.class.php文件中: ``` function cert_action(){ $id=$_GET['id']; $arr=@explode("|",base64_decode($id)); if($id && is_array($arr) && $arr[0] && $arr[2]==$this->config['coding']){ $row=$this->obj->DB_select_once("company_cert","`uid`='".$arr[0]."' and `check2`='".$arr[1]."'"); if(is_array($row)){ if($row[status]!=1){ $value.="`cert`=concat(`cert`,',1'),"; } $id=$this->obj->DB_update_all("company_cert","`status`='1'","`uid`='".$arr[0]."' and `check2`='".$arr[1]."'"); if($_GET['type']=="3"){ $value.="`email`='".$row['check']."'"; $id?$this->obj->DB_update_all("lt_info",$value,"`uid`='".$arr[0]."' "):""; }else{ $value.="`linkmail`='".$row['check']."'"; $id?$this->obj->DB_update_all("company",$value,"`uid`='".$arr[0]."' "):""; } $id?$this->obj->ACT_msg($this->config['sy_weburl']."/member","认证成功"):$this->obj->ACT_msg($this->config['sy_weburl'],"认证失败,联系管理员认证"); }else{ $this->obj->ACT_msg($this->config['sy_weburl'],"认证失败,请检查来路","2"); } }else{...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息