2S-SPACE漏洞修復

_ID未过滤

评论编辑commedit.asp 137行
comm_ID=Request.Form(“comm_ID”)==>comm_ID=cint(Request.Form(“comm_ID”))

网络收藏夹colledit.asp 103行
col_ID=Request.Form(“col_ID”)==>col_ID=cint(Request.Form(“col_ID”))

下载编辑downledit.asp 134行
downl_ID=Request.Form(“downl_ID”)==>downl_ID=cint(Request.Form(“downl_ID”))

性别提权member.asp 43行

Conn.ExeCute("update blog_Member SET mem_Sex="&CheckStr(Request.Form("mem_Sex"))&",mem_Email='"&CheckStr(Request.Form("mem_Email"))&"',mem_hideEmail="&hideEmail&",mem_HomePage='"&CheckStr(Request.Form("mem_HomePage"))&"',mem_Intro='"&CheckStr(Request.Form("mem_Intro"))&"'"&SQL_Add&" where mem_ID="&mem_ID&"")

<span style="color:LimeGreen">CheckStr(Request.Form("mem_Sex"))</span>==><span style="color:LimeGreen">cint(CheckStr(Request.Form("mem_Sex")))</span>

本站已經修復…. THANKS:loveshell.net

随机日志

发表评论

0 评论.

Leave a Reply



[ Ctrl + Enter ]

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

CNXCT小组的博客 is Stephen Fry proof thanks to caching by WP Super Cache