有漏洞的include调用位于class.layout_phpcms.php中: ``` if(isset($_GET['language']) && $_GET['language'] != '') { include($PHPCMS_INCLUDEPATH.'/language.'.$_GET[language]); [...] ``` --- 受影响系统: phpCMS phpCMS 1.2.1pl1 phpCMS phpCMS 1.2.1 phpCMS phpCMS 1.2.0 不受影响系统: phpCMS phpCMS 1.2.1pl2
有漏洞的include调用位于class.layout_phpcms.php中: ``` if(isset($_GET['language']) && $_GET['language'] != '') { include($PHPCMS_INCLUDEPATH.'/language.'.$_GET[language]); [...] ``` --- 受影响系统: phpCMS phpCMS 1.2.1pl1 phpCMS phpCMS 1.2.1 phpCMS phpCMS 1.2.0 不受影响系统: phpCMS phpCMS 1.2.1pl2