PHPCMSV9装在阿里云上曝有注入漏洞咱办?

打开/phpcms/modules/poster/ 中的poster.php文件,找到以下代码;
if ($_GET['group']) {
$group = " `".$_GET['group']."`";
$fields = "*, COUNT(".$_GET['group'].") AS num";
$order = " `num` DESC";
}
替换成
if ($_GET['group']) { $_GET['group'] = preg_replace('#`#', '', $_GET['group']);
$group = " `".$_GET['group']."`";
$fields = "*, COUNT(".$_GET['group'].") AS num";
$order = " `num` DESC";
}
修改前记得备份。
如果内容有帮助,就点个赞吧!
