MacCMS 6.x referer处理不当引发注射

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: MacCMS 9月份新出7.x版本不受影响 因此这个漏洞成为历史漏洞了 不过还是发出来给大家一起讨论学习一下吧 ### 详细说明: /user/service.php ``` function Popularize() { global $db; $userid = safeData("userid","get"); if (!isNum($userid)) { die("用户非法,请从新登陆!");} $Ip = getip(); $Ly = $_SERVER["HTTP_REFERER"]; $row = $db->getRow("select * from tbl_user where u_id=" . $userid .""); if ($row){ $sql="Select * From tbl_user_visit where uv_userid = " .$userid." and uv_ip ='".$Ip."' and STR_TO_DATE(uv_time,'%Y-%m-%d')='".date("Y-m-d")."'"; $rsUv = $db->query($sql); $nums= $db -> num_rows($rsUv); if ($nums==0){ $db->query("insert tbl_user_visit (uv_userid,uv_ip,uv_ly,uv_time) values('".$userid."','".$Ip."','".$Ly."','".date('Y-m-d H:i:s',time())."') "); $db->query("update tbl_user set u_popularizenum=u_popularizenum+1,u_points=u_points+".app_userpopularize." where u_id = ". $userid ); $sql="Delete From tbl_user_visit where STR_TO_DATE(uv_time,'%Y-%m-%d')<'".date("Y-m-d")."'"; $db->query($sql); } } die("<sc" . "ript...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息