ESPCMS Local File Inclusion Vulnerability

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 包含 ### 详细说明: adminsoft/index.php ``` $archive = indexget('archive', 'R'); $archive = empty($archive) ? 'adminuser' : $archive; $action = indexget('action', 'R'); $action = empty($action) ? 'login' : $action; include admin_ROOT . adminfile . "/control/$archive.php";// 包含产生 good nice $control = new important(); $action = 'on' . $action; if (method_exists($control, $action)) { $control->$action(); } else { exit('错误:系统方法错误!'); } ``` ``` 首先看index.php 02///省略无关代码 03$archive = indexget('ac', 'R'); //ac 04$action = indexget('at', 'R'); //at 05///省略无关代码 06if (empty($archive) || empty($action)) { 07 include admin_ROOT . 'interface/public.php'; 08 $mainlist = new mainpage(); 09 if (method_exists($mainlist, 'in_index')) { 10 $mainlist->in_index(); 11 } else { 12 exit('Access error!'); 13 } 14} else { 15 if (in_array($archive, array('article', 'forum', 'search', 'bbssearch', 'forummain', 'messmain', 'special', 'respond', 'public', 'scriptout', 'enquiry', 'enquirymain', 'form',...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息