Discuz! admin/database.inc.php...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

由于Discuz!的admin\database.inc.php里action=importzip解压zip文件时,导致可以得到webshell.<br /> 在文件admin\database.inc.php里代码:<br /> .....<br /> elseif($operation == 'importzip') {<br /> <br /> require_once DISCUZ_ROOT.'admin/zip.func.php';<br /> $unzip = new SimpleUnzip();<br /> $unzip->ReadFile($datafile_server);<br /> if($unzip->Count() == 0 || $unzip->GetError(0) != 0 || !preg_match("/\.sql$/i", $importfile = $unzip->GetName(0))) {<br /> cpmsg('database_import_file_illegal', '', 'error');<br /> }<br /> <br /> $identify = explode(',', base64_decode(preg_replace("/^# Identify:\s*(\w+).*/s", "\\1", substr($unzip->GetData(0), 0, 256))));<br /> $confirm = !empty($confirm) ? 1 : 0;<br /> if(!$confirm && $identify[1] != $version) {<br /> cpmsg('database_import_confirm',...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息