The category ID is not effectively filtered, resulting in injection. Details: Affected Version: PHPCMS V9-GBK vulnerability file:/phpcms/modules/special/index. php vulnerability function: type () unfiltered parameter: $ _ GET ['typeid']., Row 56th transforms the typeid, and when row 66th uses the typeid again, the typeid of the integer is not used, resulting in injection. Since PHPCMS automatically uses the addslashes function to escape the parameters of GPC, I think it is possible to succeed only when wide byte injection is used in GBK. Because I did not report an error in the program during the test, [this occurs in the informal test below], [for me to forcibly change the field name typeid of 66 rows to typeid1 to enable SQL to report an error ], displays the currently executed SQL... From the SQL point of view, the injection is successful.
If the test is successful, leave a comment. I have finished the test. Solution:
Www.2cto.com: the latest official patch has been fixed. please patch it in time.