WoDig社区程序Members.asp页面过滤不严导致SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

在文件Members.asp中: SearchType=HTMLEncode(Request("SearchType")) //第38行 SearchText=HTMLEncode(Request("SearchText")) SearchRole=HTMLEncode(Request("SearchRole")) CurrentAccountStatus=HTMLEncode(Request("CurrentAccountStatus")) JoinedDateComparer=Left(Request("JoinedDateComparer"),1) LastPostDateComparer=Left(Request("LastPostDateComparer"),1) JoinedDate_picker=HTMLEncode(Request("JoinedDate_picker")) LastPostDate_picker=HTMLEncode(Request("LastPostDate_picker")) if SearchType="all" then SearchType="UserEmail like '%"&SearchText&"%' or UserName" if SearchText<>"" then item=item&" and ("&SearchType&" like '%"&SearchText&"%')" if JoinedDate_picker<>"" and JoinedDateComparer<>"" then item=item&" and...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息