You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
�
follow up $mfuncApp->app_name
Concatenate $copyright, $identifier directly, then return.
Go back to $id=$mfuncApp->createApp($module,$app,array('name'=>$name,'methods'=>$methods));
Vulnerability conditions
Vulnerability details
Location: /SkycaijiApp/admin/controller/Develop.php#L707#funcAction()
Code:
Vulnerability key code:
�
follow up $mfuncApp->app_name
Concatenate $copyright, $identifier directly, then return.
Go back to
$id=$mfuncApp->createApp($module,$app,array('name'=>$name,'methods'=>$methods));
follow up $mfuncApp->createApp
$module,$app,array('name'=>$name,'methods'=>$methods)
And the parameters we can control,follow up
$funcFile=$this->filename($module,$app);
Return directly after splicing
Continue back to the createApp function
There is no filter /* and */ for variables $name
/plugin/func/$module/$copyright$identifier.php
Exp is constructed directly here:
check the file
Visit /plugin/func/downloadImg/A11B1.php
post: a=command
The text was updated successfully, but these errors were encountered: