ecshop SQL注入漏洞导致代码执行

ecshop SQL注入漏洞导致代码执行
11208761
/includes/lib_insert.php
云盾自研
2017-03-06 06:29:40
ecshop的/includes/lib_insert.php文件中,对输入参数未进行正确类型转义,导致整型注入的发生。
139c139,140
+       $arr['num'] = intval($arr['num']);
+       $arr['id'] = intval($arr['id']);
267c268
---
270c271,272
+       $arr['id'] = intval($arr['id']);
+       $arr['type'] = addslashes($arr['type']);
308c310
---
+       $arr['id'] = intval($arr['id']);




猜你喜欢

转载自blog.csdn.net/wangshuai6707/article/details/60570052