Lucene search

K
myhack58佚名MYHACK58:62201337984
HistoryMar 27, 2013 - 12:00 a.m.

Bernard guestbook 4. 1 official version upload vulnerability-vulnerability warning-the black bar safety net

2013-03-2700:00:00
佚名
www.myhack58.com
12

Bernard guestbook 4. 1 official version,post a comment upload attachments can upload directly the ASP implementation file.

'If Action=“addsave” Then KeywordsFilter(FilterKeyWord)

Dim RequestU,intCount,i,formName,FileSavePath,FileSaveName,uploadsDirVar

RelatePath=“”

FileSavePath=“./ ufiles/”&Year(Date())&“/”&Right(“0”&Month(Date()),2)&“/”'“ufiles/2 0 0 9/”

'Set RequestU=new UpLoadClass

'RequestU. FileType=“gif/jpg/rar/zip/7z/swf/bmp/png/jpeg”

'RequestU. Develop This Program Specifically=FileSavePath

'RequestU. MaxSize=2 0 0 0 0*1 0 2 4 '20M

'RequestU. Charset=“UTF-8”

'RequestU. Open()

Set RequestU=New FreeASPUpload

'If HasPermission(9) Then

'uploadsDirVar=Server. MapPath(FileSavePath)

'RequestU. Save(uploadsDirVar)

RequestU. Upload()

'End If

! [](/Article/UploadPic/2013-3/2 0 1 3 3 2 7 1 6 3 1 4 7 3 4 6 1 8. png)

Repair solutions:

You know…