shopex PHP Notice,SHOPEX 4.8.5 最新注入漏洞后台拿SHELL

SHOPEX 4.8.5 注入漏洞以及后台拿SHELL

漏洞文件:

漏洞核心函数 \core\model_v5\trading\mdl.goods.php

漏洞代码:

public function getProducts( $gid, $pid = 0 )

{

$sqlWhere = "";

if ( 0 < $pid )

{

$sqlWhere = " AND A.product_id = ".$pid; // 没过滤 ~~~~~~

}

$sql = "SELECT A.*,B.image_default FROM sdb_products AS A LEFT JOIN sdb_goods AS B ON A.goods_id=B.goods_id WHERE A.goods_id=".intval( $gid ).$sqlWhere;

return $this->db->select( $sql );

}

\core\shop\controller\ctl.product.php 文件调用

function gnotify($goods_id=0,$product_id=0){

if($_POST['goods']['goods_id']){

$goods_id = $_POST['goods']['goods_id'];

$product_id = $_POST['goods']['product_id'];

}

$this->id =$goods_id;

$objGoods = &$this->system->loadModel('trading/goods');

$aProduct = $objGoods->getProducts($goods_id, $product_id);// 直接带进去了

$this->pagedata['goods'] = $aProduct[0];

if($this->member[member_id]){

$objMember = &$this->system->loadModel('member/member');

$aMemInfo = $objMember->getFieldById($this->member[member_id], array('email'));

$this->pagedata['member'] = $aMemInfo;

}

$this->output();

}

漏洞官方解决办法:http://bbs.shopex.cn/read.php?tid-269636.html

开心洋葱 , 版权所有丨如未注明 , 均为原创丨未经授权请勿修改 , 转载请注明SHOPEX 4.8.5 最新注入漏洞后台拿SHELL!

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值