【网络安全】CmsEasy 漏洞挖掘

写在前面

在index.php ,定义了一些常量,设置 文件包含的目录,和注册了自定义加载类。

[<img src=“https://p3-juejin.byteimg.com/tos-cn-i-k3u1fbpfcp/e815c7db0d6d45d88e42805cef82fdd7~tplv-k3u1fbpfcp-zoom-in-crop-mark:4536:0:0:0.image)](https://link.juejin.cn/?target=https%3A%2F%2Fwww.oschina.net%2Faction%2FGoToLink%3Furl%3Dhttps%253A%252F%252Fj1ang.oss-cn-hangzhou.aliyuncs.com%252Fimg%252F1631601869827-11e3f6bd-359a-4da0-8521-f43ab1df937d.png “https://www.oschina.net/action/GoToLink?url=https%3A%2F%2Fj1ang.oss-cn-hangzhou.aliyuncs.com%2Fimg%2F1631601869827-11e3f6bd-359a-4da0-8521-f43ab1df937d.png”” style=“margin: auto” />

[<img src=“https://p3-juejin.byteimg.com/tos-cn-i-k3u1fbpfcp/0918dfba86d5439b9c0d8d81dbaa890a~tplv-k3u1fbpfcp-zoom-in-crop-mark:4536:0:0:0.image)](https://link.juejin.cn/?target=https%3A%2F%2Fwww.oschina.net%2Faction%2FGoToLink%3Furl%3Dhttps%253A%252F%252Fj1ang.oss-cn-hangzhou.aliyuncs.com%252Fimg%252F1631602030076-26a06bc1-8fc8-4436-83d8-8e7611c37af3.png “https://www.oschina.net/action/GoToLink?url=https%3A%2F%2Fj1ang.oss-cn-hangzhou.aliyuncs.com%2Fimg%2F1631602030076-26a06bc1-8fc8-4436-83d8-8e7611c37af3.png”” style=“margin: auto” />

lib目录中前两个文件夹分别存放的是后台和前台的控制器。

inc文件夹提供一些必要的支撑,数据库的操作,以及控制器的基类,模板渲染类。

[<img src=“https://p3-juejin.byteimg.com/tos-cn-i-k3u1fbpfcp/9b143c8cd2624bfaa871989ee95f1638~tplv-k3u1fbpfcp-zoom-in-crop-mark:4536:0:0:0.image)](https://link.juejin.cn/?target=https%3A%2F%2Fwww.oschina.net%2Faction%2FGoToLink%3Furl%3Dhttps%253A%252F%252Fj1ang.oss-cn-hangzhou.aliyuncs.com%252Fimg%252F1631602330700-0bc0e406-e0ec-4d5f-a186-6fc1bd0cc922.png “https://www.oschina.net/action/GoToLink?url=https%3A%2F%2Fj1ang.oss-cn-hangzhou.aliyuncs.com%2Fimg%2F1631602330700-0bc0e406-e0ec-4d5f-a186-6fc1bd0cc922.png”” style=“margin: auto” />

所有的控制器都继承于 act 类。同时他还给所有数据库的表,设计了相对应的操作,位于table文件夹下,此文件夹下的类也都继承于 table类。

tool文件夹存放一些小工具,自定义函数,waf之类的,应用调度,也是在此文件夹处理。

继续跟进入口文件。

[<img src=“https://p3-juejin.byteimg.com/tos-cn-i-k3u1fbpfcp/2ceb8477868c49a3b7e9a3741ae6f4e9~tplv-k3u1fbpfcp-zoom-in-crop-mark:4536:0:0:0.image)](https://link.juejin.cn/?target=https%3A%2F%2Fwww.oschina.net%2Faction%2FGoToLink%3Furl%3Dhttps%253A%252F%252Fj1ang.oss-cn-hangzhou.aliyuncs.com%252Fimg%252F1631601922667-cc023a4a-cd54-4542-bd4b-abe40d09c0cc.png “https://www.oschina.net/action/GoToLink?url=https%3A%2F%2Fj1ang.oss-cn-hangzhou.aliyuncs.com%2Fimg%2F1631601922667-cc023a4a-cd54-4542-bd4b-abe40d09c0cc.png”” style=“margin: auto” />

实例化了 front对象,并调用 dispatch 方法。

他的构造方法就是获取对应的参数,

[<img src=“https://p3-juejin.byteimg.com/tos-cn-i-k3u1fbpfcp/0699310a77b1495287b82f233855c5a6~tplv-k3u1fbpfcp-zoom-in-crop-mark:4536:0:0:0.image)](https://link.juejin.cn/?target=https%3A%2F%2Fwww.oschina.net%2Faction%2FGoToLink%3Furl%3Dhttps%253A%252F%252Fj1ang.oss-cn-hangzhou.aliyuncs.com%252Fimg%252F1631602793440-61666943-daec-4767-ac41-87ec7705ed48.png “https://www.oschina.net/action/GoToLink?url=https%3A%2F%2Fj1ang.oss-cn-hangzhou.aliyuncs.com%2Fimg%2F1631602793440-61666943-daec-4767-ac41-87ec7705ed48.png”” style=“margin: auto” />

[<img src=“https://p3-juejin.byteimg.com/tos-cn-i-k3u1fbpfcp/a3584bc51cac415e8d45032791db3f43~tplv-k3u1fbpfcp-zoom-in-crop-mark:4536:0:0:0.image)](https://link.juejin.cn/?target=https%3A%2F%2Fwww.oschina.net%2Faction%2FGoToLink%3Furl%3Dhttps%253A%252F%252Fj1ang.oss-cn-hangzhou.aliyuncs.com%252Fimg%252F1631602855207-01b8a2f5-1b58-46a1-9b2a-2e347043f10b.png “https://www.oschina.net/action/GoToLink?url=https%3A%2F%2Fj1ang.oss-cn-hangzhou.aliyuncs.com%2Fimg%2F1631602855207-01b8a2f5-1b58-46a1-9b2a-2e347043f10b.png”” style=“margin: auto” />

同时对所有的请求进行转义和html实体的处理。

[<img src=“https://p3-juejin.byteimg.com/tos-cn-i-k3u1fbpfcp/7784256c8bab4f16b2638d1c0c997bda~tplv-k3u1fbpfcp-zoom-in-crop-mark:4536:0:0:0.image)](https://link.juejin.cn/?target=https%3A%2F%2Fwww.oschina.net%2Faction%2FGoToL

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值