Bo-blog v2.1.1 注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

inc/mod_main.php //漏洞文件: case 'category': if (!$job) $job='default'; else $job=basename($job); $ifannouncement="none"; acceptrequest('mode'); if ($mode==1 || $mode==2) { //.......................... } elseif (!empty($mode) && (!is_numeric($mode) || $mode>2)) { getHttp404($lnc[313]); } //...................... if (is_numeric($itemid)) $itemid=floor($itemid); //注意1 elseif (isset($categorynames[$itemid])) $itemid=floor($categorynames[$itemid]);//注意2 else { getHttp404($lnc[186]); //注意3 } if (is_array($categories[$itemid]['subcates'])) { $categories[$itemid]['subcates'][]=$itemid; $all_needed_cates=@implode(',', $categories[$itemid]['subcates']); } else { $all_needed_cates=$itemid;// } $counter_now=$blog->countbyquery("SELECT COUNT(blogid) FROM `{$db_prefix}blogs` {$limitation2}`category` in ({$all_needed_cates})"); //........................... index.php //调用文件: acceptrequest('act,go,page,part'); if (!$page) $page=1; elseif (!is_numeric($page) ||...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息