Discuz!7.0-7.2后台settings.inc.php中写shell漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

漏洞详情: if($operation == 'uc' && is_writeable('./config.inc.php') && $isfounder) { $ucdbpassnew = $settingsnew['uc']['dbpass'] == '********' ? UC_DBPW : $settingsnew['uc']['dbpass']; if($settingsnew['uc']['connect']) { $uc_dblink = @mysql_connect($settingsnew['uc']['dbhost'], $settingsnew['uc']['dbuser'], $ucdbpassnew, 1); if(!$uc_dblink) { cpmsg('uc_database_connect_error', '', 'error'); } else { mysql_close($uc_dblink); } } $fp = fopen('./config.inc.php', 'r'); $configfile = fread($fp, filesize('./config.inc.php')); $configfile = trim($configfile); $configfile = substr($configfile, -2) == '?>' ? substr($configfile, 0, -2) : $configfile; fclose($fp); $connect = ''; if($settingsnew['uc']['connect']) { require './config.inc.php'; $connect = 'mysql'; $samelink = ($dbhost == $settingsnew['uc']['dbhost'] && $dbuser == $settingsnew['uc']['dbuser'] && $dbpw == $ucdbpassnew); $samecharset = !($dbcharset == 'gbk' && UC_DBCHARSET == 'latin1' ||...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息