Commit Graph

254 Commits

Author SHA1 Message Date
xiaomlove
f8c745e4b4 fix english readme link 2021-05-20 14:12:18 +08:00
xiaomlove
99a3b057ee improve-readme 2021-05-20 14:06:56 +08:00
xiaomlove
88207b9975 add-trans 2021-05-19 19:45:41 +08:00
CZ
ce05680219 修复3个安全漏洞 (#15)
* 修复趣味盒未授权访问漏洞

趣味盒页面未做鉴权游客可以任意查看或发送内容

* 修复sql注入漏洞

* 修复sql注入 详见描述

代码第19行		if (!is_valid_id($class) && $class != 0)
如果class 为"sleep(5)" 虽然过不了is_valid_id校验 但是由于php 弱类型 非数字开头的字符串 最终会判断为 $class = 0 绕过了校验
另外建议is_valid_id 改为更直接的intval 将用户输入的的数据强制转换成int 防止sql注入
2021-05-19 13:49:41 +08:00
xiaomlove
0c136b7743 api add page_title 2021-05-18 02:37:39 +08:00
xiaomlove
e5a9dc3273 dashboard latest user gender 2021-05-17 21:17:30 +08:00
xiaomlove
6e4c168cd5 dashboard latest torrent limit 5 2021-05-17 21:15:18 +08:00
xiaomlove
7edc385cdc build dashboard 2021-05-17 21:09:02 +08:00
xiaomlove
d651762c1b Dashboard 2021-05-17 21:07:50 +08:00
xiaomlove
fa4f9a29c5 snatch list paginate 2021-05-17 00:56:23 +08:00
xiaomlove
d598c57891 snatch speed 2021-05-17 00:44:35 +08:00
xiaomlove
b2067c9424 snatch only get finished 2021-05-17 00:38:42 +08:00
xiaomlove
cd46d8ef38 api snatch controller 2021-05-17 00:11:42 +08:00
xiaomlove
6789e7e5ea api snatches 2021-05-17 00:10:15 +08:00
xiaomlove
3d7ab7a7dc cast peer finishedat datetime 2021-05-16 15:03:02 +08:00
xiaomlove
6ccf135b6c api peer list 2021-05-16 14:44:02 +08:00
xiaomlove
d2bb1e7944 change format description func delimiter 2021-05-16 03:04:58 +08:00
xiaomlove
7dee44140b define constant fix 2021-05-16 02:57:00 +08:00
xiaomlove
17e92f885b define NEXUS_START in api 2021-05-16 00:35:48 +08:00
xiaomlove
33e99516b6 torrent api + swip constants 2021-05-15 19:29:44 +08:00
xiaomlove
786095ca96 remove UC_FORUM_MODERATOR 2021-05-15 13:16:30 +08:00
xiaomlove
73f9920e1f enable user handle leechwarn 2021-05-15 12:59:59 +08:00
xiaomlove
682cf806d7 migrate disable&enable user basic 2021-05-15 03:21:06 +08:00
xiaomlove
dea20254bf exam user show is_done 2021-05-15 02:13:33 +08:00
xiaomlove
a0bb422a58 fix: cronjobBackup now minute 2021-05-15 01:45:15 +08:00
xiaomlove
21d87ca49f admin setting backup + backupCronjob 2021-05-15 01:24:44 +08:00
xiaomlove
47f64f2c5c [admin] add setting backup 2021-05-14 20:41:43 +08:00
xiaomlove
6c85176e2f fix warning 2021-05-14 11:04:03 +08:00
xiaomlove
6d3068eb8c add disable user method 2021-05-14 02:11:57 +08:00
xiaomlove
0742ed33f8 fix torrent_info.php 404 2021-05-14 01:20:41 +08:00
xiaomlove
514294530c fix warning: Undefined array key 2021-05-14 01:00:59 +08:00
xiaomlove
12b370f2e8 db structure add table user_ban_logs 2021-05-14 00:31:37 +08:00
xiaomlove
89c2a05d50 cleanup: change inactive user translation 2021-05-13 21:41:36 +08:00
xiaomlove
8963058463 add user ban log from cleanup.php 2021-05-13 21:31:09 +08:00
xiaomlove
174fd2f180 user modcomment new new one in the front 2021-05-12 13:56:45 +08:00
xiaomlove
70f1f31dcc user ban log 2021-05-12 13:45:00 +08:00
xiaomlove
02d7eb4e93 invites add register info 2021-05-11 11:22:58 +08:00
xiaomlove
0aa0d7afa7 invite after signup do not delete 2021-05-11 02:44:43 +08:00
xiaomlove
fa57e78c74 backup add feature: upload to google drive 2021-05-11 01:41:58 +08:00
xiaomlove
3e4471f533 add-filesystem-google-drive 2021-05-10 20:05:52 +08:00
xiaomlove
3edc75b844 rebuild admin fix exam create 2021-05-09 22:37:26 +08:00
xiaomlove
2acb6e6f17 fix: exam create index disappeared 2021-05-09 22:32:36 +08:00
xiaomlove
1f7251894f beta6 2021-05-08 18:34:23 +08:00
xiaomlove
e29bac1033 add command user:reset_password 2021-05-08 18:27:35 +08:00
xiaomlove
cd8407c8ca add complete requirements form extensions 2021-05-08 17:58:28 +08:00
xiaomlove
bd1ab5fc9a fix duration_text attribute 2021-05-08 16:31:19 +08:00
xiaomlove
d23a85a888 fix exam duration 2021-05-08 16:25:55 +08:00
xiaomlove
5241780cdd store-exam-validate 2021-05-07 18:30:58 +08:00
xiaomlove
3853b95adc fix location.php config() error 2021-05-07 02:33:17 +08:00
xiaomlove
979c1d8110 admin-add-setting 2021-05-06 19:37:07 +08:00