PHPCMSV9中poster.php注入漏洞修复方法

PHPCMSV9装在阿里云上曝有注入漏洞咱办?

5e192d20843f2

打开/phpcms/modules/poster/ 中的poster.php文件,找到以下代码;

if ($_GET['group']) {
    $group = " `".$_GET['group']."`";
    $fields = "*, COUNT(".$_GET['group'].") AS num";
    $order = " `num` DESC";
}

替换成

if ($_GET['group']) { $_GET['group'] = preg_replace('#`#', '', $_GET['group']);
    $group = " `".$_GET['group']."`";
    $fields = "*, COUNT(".$_GET['group'].") AS num";
    $order = " `num` DESC";
}

修改前记得备份。

如果内容有帮助,就点个赞吧!

转载注明出处:http://www.12564.cn/show-5.html

如有疑问请联系 QQ:644233191   微信:zw1688k