php168 5.0 job.php 信息泄漏漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 漏洞分析 看job.php 92行 ``` elseif($job=="download") { $rsdb=$db->get_one("SELECT * FROM {$pre}article WHERE aid='$id'"); $fidDB=$db->get_one("SELECT * FROM {$pre}sort WHERE fid='$rsdb[fid]'"); if($fidDB[admin]&&$lfjid){ $detail=explode(",",$fidDB[admin]); if( in_array($lfjid,$detail) ){ $web_admin=1; } } if($fidDB[allowdownload]&&!$web_admin&&$lfjuid!==$rsdb[uid]){ $detail=explode(",",$fidDB[allowdownload]); if( !in_array($groupdb['gid'],$detail) ){ showerr("你所在的用户组无权限下载"); } } if($rsdb[allowdown]&&!$web_admin&&$lfjuid!==$rsdb[uid]){ $detail=explode(",",$rsdb[allowdown]); if( !in_array($groupdb['gid'],$detail) ){ showerr("你所在的用户组无权限下载"); } } $url=base64_decode($url); if( eregi(".php",$url) ){ die("ERR"); } $fileurl=str_replace($webdb[www_url],"",$url); if(is_file(PHP168_PATH."$fileurl")&&filesize(PHP168_PATH."$fileurl")<1024*1024*500){ $filename=basename($fileurl); $filetype=substr(strrchr($filename,'.'),1);...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息