A function parallel permission vulnerability in hunting Network
When I passed a recruitment website, I threw my resume! Http://c.liepin.com/
Because no comics are made, you can directly describe the text:
Http://article.liepin.com/ask/qa196028 this is a question and answer that can be beyond the authority to delete anyone's answer! (Check the vulnerability proof !)
Http://c.liepin.com/resume/getdefaultresume/ this is profile (requires registration login) here, you can delete anyone's [Work Experience], [educational experience], [language ability], [project experience], [self-evaluation], and [Additional information. (Check the image proof in the vulnerability !)
Here we can use the BP Intruder function to help you directly clear the database. I am not doing that ~~ I just registered two accounts and tested each other. Because the number is more than, clearing the database is a matter of minutes. You know.
Solution:
The res_id_encode already has this parameter. Why not perform verification? So what should we do.