Replacement of php Strings

Source: Internet
Author: User

Source: phpevals BLOG
Author: phpeval

Filtering and replacement are of course good. Recently, I helped my sister buy a Korean dish. Searching for half a day. I found a station that is said to be capable of selling Korean things. I am going to buy it. But it was too early (in the morning) and they didn't seem to have gotten up yet. QQ did not respond. So I want to test the security of their website. I checked the website. Ecshop2.1.5 is used. Now it seems that all of them have reached 2.6. GOOGLE 2.1.5 does not seem to have published any vulnerabilities. The next one is coming back.
It is interesting to see a place:
About 130 lines of comment. php have a UDF.

Function add_comment ($ cmt) {/* comment whether review is required */$ status = 1-$ GLOBALS [_ CFG] [comment_check]; /* Save the comment */$ SQL = "INSERT ". $ GLOBALS [ecs]-> table (comment ). "". "(comment_type, id_value, email, user_name, content, comment_rank, add_time, ip_address, status, parent_id ". ") VALUES (". "". $ cmt-> type. ",". $ cmt-> id. ",". $ cmt-> email. ",". $ cmt-> username. ",". "". str_replace (\\,\, $ cmt-> content ). ",". $ cmt-> rank. ",". time (). ",". real_ip (). ", $ status, 0)"; clear_cache_files (comments_list.lbi); return $ GLOBALS [db]-> query ($ SQL );}

This is the main thing.

Str_replace (\\,\, $ cmt-> content) // (by: phpeval)

As a result, \ is replaced with \ to construct an appropriate statement. You can inject it.

Submit \ enter the program and then change \\
What function does it pass through. It will become \
Then they are replaced. It becomes \

Test method: Send a post to capture a package. Then comment on the location. Add one.
You will see an error.

However, the target website database is mysql 4.0.24. No way to subquery. You can only win him by another means. The version 2.6.1 of ecshop is released. It seems that this is not the case.

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.