ymcms SQL注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

forum_zoom.php 31~48行 if ($forumid != &quot;&quot;){ $isforum = &quot; &amp;&amp; forumid IN (&quot;.$forumid.&quot;) &quot;; }else{ $isforum = &quot;&quot;; } //forumid明显没有过滤 …… $sql = &quot;Select threadid, title, lastpost FROM &quot;.$ym_thread_tab.&quot; Where isshow=&quot;1&quot; &quot;.$isforum.&quot; orDER BY &quot;.$isaction.&quot; LIMIT 0, &quot;.$shownum; 发生了注射 ymcms3.1.0 <a href="http://www.ymcms.com/" target="_blank">http://www.ymcms.com/</a>

0%
暂无可用Exp或PoC
当前有0条受影响产品信息