ESPCMS SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: SQL注入 ### 详细说明: ``` $membercookieview = $this->member_cookieview(); if (!empty($membercookieview['userid']) && !empty($membercookieview['username'])) { $rsMember = $this->get_member(null, $membercookieview['userid']); } $this->pagetemplate->assign('member', $rsMember); } $cartid = $this->fun->accept('ecisp_enquiry_list', 'C'); $cartid = stripslashes(htmlspecialchars_decode($cartid)); $uncartid = !empty($cartid) ? unserialize($cartid) : 0; if ($uncartid && is_array($uncartid)) { $didarray = $this->fun->key_array_name($uncartid, 'did', 'amount'); $didlist = $this->fun->format_array_text(array_keys($didarray), ','); if (!empty($didlist)) { $db_table = db_prefix . 'document'; $db_where = "isclass=1 AND did in($didlist) ORDER BY did DESC"; echo $sql = "SELECT * FROM $db_table WHERE $db_where"; $rs = $this->db->query($sql); $productmoney = 0; while ($rsList = $this->db->fetch_assoc($rs)) { $rsList['link'] = $this->get_link('doc', $rsList, admin_LNG); $rsList['buylink'] =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息