yunsle

Results 3 issues of yunsle

期待开源,佩服动手能力

In hdcms 5.7, attacker can upload evil file via /js/hdjs/package/webuploader/server/fileupload.php, which leads to Arbitrary Code Execution vulnerability. ![image](https://user-images.githubusercontent.com/18137763/60377943-10b5fe80-9a4e-11e9-8276-8c4047d39bd1.png) ![image](https://user-images.githubusercontent.com/18137763/60377968-570b5d80-9a4e-11e9-93dc-0150dbea81af.png) ![image](https://user-images.githubusercontent.com/18137763/60377973-5ecb0200-9a4e-11e9-96cc-b52d7079b48c.png)

情况标题所述,收到转账后进入我的->消息,点击到账信息想看详情时闪退