KesionCMS V9.03 Final SQL注射漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 昨天提交科讯getshell的洞,通知官方后,说是V9移除wap模块..... 然后就没下文了,好吧,那就来个V9的 ### 详细说明: 漏洞存在于User/ChinaBankAutoReceive.asp ``` <%@LANGUAGE="VBSCRIPT" CODEPAGE="936"%> <%option explicit%> <!--#include file="../Conn.asp"--> <!--#include file="../Plus/md5.asp"--> <!--#include file="../KS_Cls/Kesion.MemberCls.asp"--> <!--#include file="payfunction.asp"--> <% '**************************************************** ' Software name:Kesion CMS 9.0 ' Email: service@kesion.com . QQ:111394,9537636 ' Web: http://www.kesion.com http://www.kesion.cn ' Copyright (C) Kesion Network All Rights Reserved. '**************************************************** Response.Buffer = true Response.Expires = 1 Response.CacheControl = "no-cache" Dim KSUser:Set KSUser=New UserCls Dim KS:Set KS=New PublicCls Dim PaymentPlat:PaymentPlat=1 Dim RSP:Set RSP=Server.CreateObject("ADODB.RECORDSET") RSP.Open "Select top 1 * From KS_PaymentPlat where id=" & PaymentPlat,conn,1,1 If RSP.Eof Then RSP.Close:Set RSP=Nothing...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息