OBLOG Class_UserCommand.asp注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

文件In/Class_UserCommand.asp : strMonth=Request(&quot;month&quot;) //第63行 strDay=Request(&quot;day&quot;) …… Case &quot;month&quot; //第84行 Dim LastDay G_P_FileName = G_P_FileName &amp; &quot;month&amp;month=&quot; &amp; strMonth strDay=Left(strMonth,4) &amp; &quot;-&quot; &amp; Right(strMonth,2) &amp; &quot;-01&quot; mYear=Left(strMonth,4) mMonth=Right(strMonth,2) If InStr (&quot;01,03,05,07,08,10,12&quot;,mMonth)&gt; 0 Then LastDay = &quot;31&quot;…… Else //第109行 SqlPart = &quot; And Addtime &gt;='&quot;&amp;strMonth&amp;&quot;01' AND Addtime &lt; '&quot;&amp;strMonth&amp;LastDay&amp;&quot;' &quot; 构造合适的变量strMonth进行注射 Oblog 4.5-4.6 sql 暂无 <a href=www.oblog.cn target=_blank>www.oblog.cn</a>

0%
暂无可用Exp或PoC
当前有0条受影响产品信息