by Ryat
http://www.wolvez.org
2009-10-24
本来想给论坛加个上传附件的功能,从官方网站下了个pun_attachment,顺便看了下代码,结果发现了这个漏洞:
{
if (preg_match('~(\d+)f(\d+)~', $_GET['secure_str'], $match))
{
...
'WHERE' => 'a.id = '.$attach_item.' AND (fp.read_forum IS NULL OR fp.read_forum =
2009-11-06 18:45
2009-11-05 16:55
2009-11-04 22:52
2009-10-29 00:06
2009-10-28 19:04
2009-10-25 22:13
2009-10-20 19:08
2009-10-20 19:03
2009-10-11 10:40
2009-10-11 10:36
|
|










