转自wooyun http://www.wooyun.org/bugs/wooyun-2014-0785911.伪造cookie登录系统(其实这一步多余的,大多用户连密码都没改,都是默认的123456)登录成功设置4个cookie,看代码function login($lusername,$lpassword,$key,$lifetime=0){
global $set_username,$set_password,$set_loginauth,$set_loginkey;
if(empty($lusername)||empty($lpassword))
{
printerror("EmptyLoginUser","index.php");
}
//验证码
if(!$set_loginkey)
{
if($keygetcvar('checkkey')||empty($key))
{
printerror("FailLoginKey","index.php");
}
}
if(md5($lusername)md5($set_username)||md5($lpassword)$set_password)
{
printerror("ErrorUser","index.php");
}
//认证码
if($se
...
继续阅读
(9)