在文件modcp\moderate.inc.php里代码:
require_once DISCUZ_ROOT.'./include/discuzcode.func.php';
require_once DISCUZ_ROOT.'./include/attachment.func.php';
$ppp = 10;
$page = max(1, intval($page));
$start_limit = ($page - 1) * $ppp;
$modcount = $db->result_first("SELECT COUNT(*) FROM {$tablepre}posts WHERE invisible='$pstat' AND first='0' $fidadd[and]$fidadd[fids]");
$multipage = multi($modcount, $ppp, $page, "admincp.php?action=modreplies&filter=$filter&fid=$fid");
$fidadd在moderate.inc.php没有初始化也没有过滤直接在数据库里进行select操作,导致可以进行sql注射攻击.
[这个文件访问需要斑主权限 :)]
0
2008-09
www.Discuz.net
暂无评论