各位大佬: 小弟在安裝Discuz! X3.4 正式版,在滲透測(cè)試階段發(fā)現(xiàn)Discuz! X3.4 正式版存在水平越權(quán)漏洞,URL地址欄直接有uid參數(shù),隨手把8改成7就變成另外一個(gè)用戶的個(gè)人設(shè)置頁(yè)面,該漏洞應(yīng)該屬于高危漏 ... 查看全文
手機(jī)版|小黑屋|Discuz! 官方交流社區(qū)
( 皖I(lǐng)CP備16010102號(hào) |皖公網(wǎng)安備34010302002376號(hào) )|網(wǎng)站地圖|
GMT+8, 2025-10-20 05:00 , Processed in 0.050823 second(s), 16 queries , Redis On.
Powered by Discuz! X5.0 Licensed
© 2001-2025 Discuz! Team.