乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2014-05-07: 细节已通知厂商并且等待厂商处理中 2014-05-07: 厂商已经确认,细节仅向厂商公开 2014-05-17: 细节向核心白帽子及相关领域专家公开 2014-05-27: 细节向普通白帽子公开 2014-06-06: 细节向实习白帽子公开 2014-06-21: 细节向公众公开
学习中......少装不努力,老大搞IT!!!
phpyun 个人会员中心member/model/index.class.php $_COOKIE["usertype"];参数存在注入,从下面代码中可以看到$data["usertype"] 直接读取COOKIE的值,带入到sql中,sql未对值进行过滤处理
function msg_action(){ if($_GET["del"]){ $nid=$this->obj->DB_delete_all("userid_msg","`id`='".$_GET["del"]."' and `uid`='".$this->uid."'"); isset($nid)?$this->obj->ACT_msg("index.php?C=msg","删除成功"):$this->obj->ACT_msg("index.php?C=msg","删除失败"); } $this->public_action(); $urlarr=array("C"=>"msg","page"=>"{{page}}"); $pageurl=$this->url("index","index",$urlarr); $this->get_page("userid_msg","`uid`='".$this->uid."' and type!='1' order by id desc",$pageurl,"20"); if($_GET["c_uid"]){ $data["c_uid"]=$_GET["c_uid"]; $data["inputtime"]=mktime(); $data["p_uid"]=$_COOKIE["uid"]; $data["usertype"]=$_COOKIE["usertype"]; $data["com_name"]=$_GET["c_name"]; $haves=$this->obj->DB_select_once("blacklist","`p_uid`=".$data["p_uid"]." and `c_uid`=".$data["c_uid"]." and `usertype`=".$data["usertype"].""); if(is_array($haves)){ $this->obj->ACT_msg($_SERVER['HTTP_REFERER'],"该用户已在您黑名单中"); }else{ $nid=$this->obj->insert_into("blacklist",$data); $this->obj->DB_delete_all("userid_msg","`uid`=".$data["p_uid"]." and `fid`=".$data["c_uid"].""," "); $nid?$this->obj->ACT_msg($_SERVER['HTTP_REFERER'],"操作成功"):$this->obj->ACT_msg($_SERVER['HTTP_REFERER'],"操作失败"); } }
function DB_select_once($tablename, $where = 1, $select = "*") { $cachename=$tablename.$where; if(!$return=$this->Memcache_set($cachename)){ $SQL = "SELECT ".$select." FROM " . $this->def . $tablename . " WHERE ".$where." limit 1"; echo $SQL; $query = $this->db->query($SQL); $return=$this->db->fetch_array($query); $this->Memcache_set($cachename,$return); } return $return; }
危害等级:低
漏洞Rank:5
确认时间:2014-05-07 11:23
感谢您的支持,我们会尽快完善并修复!
暂无