Team: t00ls Author: Cond0r
If ($ _ REQUEST ){
If (get_magic_quotes_gpc ()){
$ _ REQUEST = tao_strip ($ _ REQUEST );
} Else {
$ _ POST = tao_check ($ _ POST );
$ _ GET = tao_check ($ _ GET );
@ Extract ($ _ POST );
@ Extract ($ _ GET );
}
$ _ REQUEST = filter_xss ($ _ REQUEST, ALLOWED_HTMLTAGS );
@ Extract ($ _ REQUEST );
Simple and simple filtering
Vulnerability files
Shops. php
$ Cid = addslashes ($ _ GET ['cid']);
$ Page =! ($ _ GET ['page'])? '1': intval ($ _ GET ['page']);
$ Page2 = ($ page-1) * 15;
$ Num1 = 15;
$ SQL = "select * from 2taoke_shopcats where cid = '$ cid '";
$ Rs = $ db-> query ($ SQL );
While ($ row = $ db-> fetch_array ($ rs )){
$ Catname = $ row ['catname'];
}
$ SQL = "select * from 2taoke_shops where cid = '$ cid '";
$ Rs = $ db-> query ($ SQL );
$ Num = mysql_num_rows ($ rs );
$ SQL = "select * from 2taoke_shops where cid = $ cid order by level desc limit $ page2, $ num1"; // integer injection ..
$ Rs = $ db-> query ($ SQL );
Www.2cto.com fixed: Targeted Filtering