ecshop2.73 api.php 两处鸡肋注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: null ### 详细说明: switch ($_POST['act']) { case 'search_goods_list': search_goods_list(); break; case 'search_products_list': search_products_list(); break; ...... } function search_products_list() { check_auth(); ...... if (!empty($_POST['goods_id']) && is_numeric($_POST['goods_id']) || !empty($_POST['bn'])) //goods_id不为数字,bn不为空.假假得假,假真得真. { $sql = 'SELECT goods_id, last_update AS last_modify, shop_price AS price, goods_sn AS bn, goods_name AS name, goods_weight AS weight, goods_number AS store, add_time AS uptime' . ' FROM ' . $GLOBALS['ecs']->table('goods') . ' WHERE ' . empty($_POST['bn']) ? "goods_id = $_POST[goods_id]" : "goods_sn = $_POST[bn]"; //bn带入查询. $goods_data = $GLOBALS['db']->getRow($sql); ...... } function search_goods_list() { ...... $page = empty($_POST['pages']) ? 1 : $_POST['pages']; //没过滤 $counts = empty($_POST['counts']) ? 100 : $_POST['counts']; //没过滤. 1 union select 1,user() $sql = 'SELECT goods_id, last_update AS last_modify' . ' FROM ' ....

0%
暂无可用Exp或PoC
当前有0条受影响产品信息