phpok
phpok copied to clipboard
PHPOK5.4 has sensitive information disclosure and sql injection
in framework/phpok_call.php, the function _userlist has a sql injection
in some reasons, we can controll the value of variable $rs, so we can splice evil sql query
you can see, it also include sensitive information
it also has in the function _arclist_single
so we can splice evil sql query. but we should make if($rs['fields_need']) alway false
