controllers/Classified_ads.php文件的subcatid,catid,locid,areaid,type,post参数带入SQL语句导致SQL注入的产生
SQL 注入点:
http://localhost/[PATH]/index.php/classified_ads/ads/?&subcatid=[SQL]


http://localhost/[PATH]/index.php/classified_ads/ads/?&locid=[SQL]

http://localhost/[PATH]/index.php/classified_ads/ads/?&catid=[SQL]
http://localhost/[PATH]/index.php/classified_ads/ads/?&areaid=[SQL]
http://localhost/[PATH]/index.php/classified_ads/ads/?&type=[SQL]
http://localhost/[PATH]/index.php/classified_ads/ads/?&post=[SQL]
暂无评论