Illegal websites should not initiate any form of manual service requests to our staff. It is strictly prohibited to use honmau Media's technical support services and products to engage in any illegal activities. If discovered, no technical support will be provided. ×
Current location:home> news > help and support

Operation and maintenance technical services

Response time:10 minutes

How to handle problems:1-on-1 manual technical services

Working hours:Monday to Saturday 8:30-22:00

Business scope:

Website development Mini programs development Discuz operation and maintenance

Baota Operation and Maintenance Website Operation and Maintenance SSL Certificates

Operation and maintenance technology can solve difficult problems for you

search first

recommend

Baota Linux Professional Edition

It includes 13 professional version plug-ins worth more than 3500 yuan, including Web Application Firewall, website monitoring reports and exception monitoring push.

  • Baota system reinforcement
  • Website tamper-proof program
  • Nginx Firewall
  • Website Monitoring Report
advertising

Discuz! X3.4 X3.3 UC(/uc_server/data/tmp) upload execution vulnerability fixes

Discuz! X3.4 X3.3 UC(/uc_server/data/tmp)上传执行漏洞修复

Discuz! X3.4 X3.3 UC(/uc_server/data/tmp) upload execution bug fix (Alibaba Cloud hot fix): Introduction: In Discuz, uc_key is the communication key for UC client to communicate with the server. There is a code writing vulnerability in/api/uc.php in discuz, which allows hackers to write malicious code to obtain uckey, and eventually enter the background of the website, causing data leakage.

Bug name:

Discuz uc.key disclosure leads to code injection vulnerability

The webmaster reported: After an existing website was recruited,/uc_server/data/tmp was uploaded to the shell

The path of the vulnerability file reported by the webmaster: /api/uc. php

Manual restoration plan:

Editor:

/api/uc.php

Find: (39 lines)

require_once '../ source/class/class_core.php';

Revise to:

require_once '../ source/class/class_core.php'; if (method_exists("C", "app")) { $discuz = C::app(); $discuz->init(); }

Find: (273 lines)

function updateapps($get, $post) {

Revise to:

function updateapps($get, $post) { if($POST@['UC_API']) { $POST@['UC_API'] = addslashes($POST@['UC_API']); }

Scan mobile WeChat

Continue reading immediately in the Mini programs

© Website copyright and disclaimer

1.[honmau Media] independently owns the copyright of all materials on relevant pages of this website;

2. No one is allowed to copy it without the express written permission of [honmau Media];

3. The articles that do not indicate "honmau Media" on this website are all from the Internet and are only for everyone to learn and refer;

4. If there is any infringement/violation/irregularity, please contact customer service QQ or email to delete it, please understand;

5.[honmau Media] reserves the right to correct, modify and update this statement at any time.legal notice

Recently, do you want to customize and develop a Mini programs/website/hosted operation and maintenance service?
submission
Working days: 8:30 - 22:00  Online QQ customer service

customer service

Company Introduction
top