### 简要描述: 我记得我前段时间就在法客论坛发表了一个爆路径的洞洞没想还存在爆路径 ### 详细说明: http://demo.cmseasy.cn/99/index.php?case=archive&act=search 还是这里的问题 搜索http://demo.cmseasy.cn/99/index.php?case=archive&act=searchhttp://demo.cmseasy.cn/99/index.php?case=archive&act=searchhttp://demo.cmseasy.cn/99/index.php?case=archive&act=searchhttp://demo.cmseasy.cn/99/index.php?case=archive&act=searchhttp://demo.cmseasy.cn/99/index.php?case=archive&act=searchhttp://demo.cmseasy.cn/99/index.php?case=archive&act=searchhttp://demo.cmseasy.cn/99/index.php?case=archive&act=searchhttp://demo.cmseasy.cn/99/index.php?case=archive&act=search 搜索的内容越多越好 ### 漏洞证明: Warning: file_put_contents(E:\clientweb\Cmsdemo\wwwroot\99/data/hotsearch/http%3A%2F%2Fdemo.cmseasy.cn%2F99%2Findex.php%3Fcase%3Darchive%26act%3Dsearchhttp%3A%2F%2Fdemo.cmseasy.cn%2F99%2Findex.php%3Fcase%3Darchive%26act%3Dsearchhttp%3A%2F%2Fdemo.cmseasy.cn%2F99%2Findex.php%3Fcase%3Darchive%26act%3Dsearchhttp%3A%2F%2Fdemo.cmseasy.cn%2F99%2Findex.php%3Fcase%3Darchive%26act%3Dsearchhttp%3A%2F%2Fdemo.cmseasy.cn%2F99%2Findex.php%3Fcase%3Darchive%26act%3Dsearchhttp%3A%2F%2Fdemo.cmseasy.cn%2F99%2Findex.php%3Fcase%3Darchive%26act%3Dsearchhttp%3A%2F%2Fdemo.cmseasy.cn%2F99%2Findex.php%3Fcase%3Darchive%26act%3Dsearch.txt) [function.file-put-contents]: failed to open stream: No such file or directory in E:\clientweb\Cmsdemo\wwwroot\99\lib\default\archive_act.php on line 228 路径就出来了 [<img src="https://images.seebug.org/upload/201207/242327186216cfadf1987706910fa654b2e338da.jpg" alt="" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201207/242327186216cfadf1987706910fa654b2e338da.jpg)