Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ecshop rce的一个bug #45

Open
Lucifer1993 opened this issue Jul 26, 2019 · 0 comments
Open

ecshop rce的一个bug #45

Lucifer1993 opened this issue Jul 26, 2019 · 0 comments

Comments

@Lucifer1993
Copy link

Lucifer1993 commented Jul 26, 2019

code_eval_2.x.py这个插件代码有个bug。
code, head, html, redirect_url, log = hackhttp.http(payload,headers = headers) code, head, html, redirect_url, log = hackhttp.http(arg + "/1.php")
payload是通过sql注入写入的,所以这两个请求中可能会存在未写入完直接判断,如果不通过延时来给写入时间的话 ,那么第二个requests已经在写入前就执行了。。所以判断会存在误差

@Lucifer1993 Lucifer1993 changed the title ecshop rce ecshop rce的一个bug Jul 26, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant