官网链接: http://www.lokicms.com/
影响版本:<= 0.3.4
### 概述:
LokiCMS 0.3.4及之前版本中的index.php存在目录遍历漏洞。当magic_quotes_gpc被中止时,远程攻击者可以借助页参数中的"..",来检查任意文件是否存在。
### 漏洞页面:
vuln file: index.php
### 漏洞代码:
```
if ( isset ( $_GET ) && isset ( $_GET['page'] ) ) $pagename = stripslashes ( trim ( $_GET['page'] ) );
// load the page
if ($pagename == '') {
$name = $c_default;
$nosimple = true;
} else {
$name = $pagename;
};
if ($c_simplelink == true && $nosimple != true) {
$content = findpage($name);
if ($content == "") {$content = $c_default;};
} else {
$content = $name;
};
// stupid fix due to subdomain problems
if ($c_modrewrite != true && $pagename != '') {if (file_exists(PATH . "/pages/" . $content) == false) {$content = $c_default;};};
// load the menu
$menu = getmenu($content, $c_modrewrite, $c_simplelink);
$content = parsepage($content);
```
暂无评论