phpecms1.3 cookies欺骗漏洞进后台
phpecms1.3/admin/cms_check.php
<?php
if(!isset($_COOKIE['admin_name'])){
alert_href('非法登录','cms_login.php');
};
?>
判断如果没有admin_name的cookie就跳登录页面,如果admin_name就不跳了。
phpecms1.3/admin/cms_welcome.php
<?php
include('../system/inc.php');
include('cms_check.php');
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<?php include('inc_head.php') ?>
</head>
<body>
<?php include('inc_header.php') ?>
<div id="content">
<div class="container">
<div class="line-big">
<?php include('inc_left.php') ?>
<div class="xx105">
<div