水木社群全站原始碼洩露 涉及大量文件資訊

2021-12-29 22:11:40 字數 2416 閱讀 7389



#1 概述漏洞發現原由水木二站的svn資訊洩露漏洞位址:

#2 結果這是乙個沒有訪問控制的svn伺服器

#3 水木社群的原始碼全在這裡

svn co ./kbs

/* 資料庫相關 */

define("db_enabled", true);

$dbuser = "wforum";

$dbpasswd = "****atp";

$dbname = "wforum";

/* 其他附加功能 */

define("showtelnetparam", false);

define("allow_sysop_multiquery", true);

define('allow_self_multiquery', true);

define("support_tex", true);

define("onboard_users", true);

if (!defined('_bbs_www2_board_php_'))

function undo_html_format($str)

if (version_compare(php_version,'5','>='))

require_once('domxml-php4-to-php5.inc.php'); //load the php5 converter

# iterate through an array of nodes

# looking for a text node

# return its content

function get_content($parent)

# get the content of a particular node

function find_content($parent,$name)


create table if not exists `board_user` (

`board` varchar(32) collate gbk_bin not null,

`user` varchar(32) collate gbk_bin not null,

`time` timestamp not null default current_timestamp on update current_timestamp,

`status` int(11) not null,

`manager` varchar(32) collate gbk_bin not null,

`score` int(11) not null,

`flag` bigint(20) not null,

unique key `member` (`board`,`user`),

key `board` (`board`),

key `user` (`user`),

key `time` (`time`),

key `flag` (`flag`),

key `status` (`status`),

key `score` (`score`)

) engine=innodb default charset=gbk collate=gbk_bin;


# 刪除水木二站的svn問題# svn server 加入鑑權機制

數學與演算法 摘自水木


