漏洞分析module/client/control.php:86参数直接传入 module,跟进 downloadZipPackage 函数,全局搜索发现有两个downloadZipPackage函数:module/client/ext/model/xuanxuan.php:10对 link ...
漏洞分析module/client/control.php:86参数直接传入 module,跟进 downloadZipPackage 函数,全局搜索发现有两个downloadZipPackage函数:module/client/ext/model/xuanxuan.php:10对 link ...