taocms icon indicating copy to clipboard operation
taocms copied to clipboard

There is SQL blind injection at "Management article"

Open win1498419293 opened this issue 3 years ago • 0 comments

1.The location of the vulnerability is line 59 in taocms\include\Model\Cms.php, and the incoming sql statement in the update() method does not use intval to process id The location of the vulnerability is line 59 in taocms\include\Model\Cms.php, and the incoming sql statement in the update() method does not use intval to process id image

2.Log in to the background as the default account admin. image image 3.You can see action=cms&ctrl=update&id=26, this id is the id in the update method in the Cms.php file image image image 3.Test using the SQLMap tool image

win1498419293 avatar Dec 11 '21 13:12 win1498419293