### 简要描述:
RT
### 详细说明:
问题出现在个人相册处:
首先我本地搭建个最新版的dz
1.先用test账号上传个图片进行权限设置 - 自己可见
[<img src="https://images.seebug.org/upload/201412/021824482c74a2cdf816fca2e0d2077586e71dc2.png" alt="1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/021824482c74a2cdf816fca2e0d2077586e71dc2.png)
[<img src="https://images.seebug.org/upload/201412/0218254634a91eee65347ad6091af54b05527aeb.png" alt="2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/0218254634a91eee65347ad6091af54b05527aeb.png)
2.用test111账号查看test账号的相册内容 显示加密
[<img src="https://images.seebug.org/upload/201412/021826277fe857f0a7d99afe814a8ac048cab093.png" alt="3.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/021826277fe857f0a7d99afe814a8ac048cab093.png)
[<img src="https://images.seebug.org/upload/201412/021827176d8624eb95e11b15d8ccd610d5f8a8c6.png" alt="4.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/021827176d8624eb95e11b15d8ccd610d5f8a8c6.png)
http://localhost/dz3.2_wwwroot/home.php?mod=space&uid=2&do=album&id=1
album&id=1 显示的是加密相册的id 记录下来
3.随便去发帖 - 选择图片 - 审查元素 - 将<option value="改成对方加密相册的ID">111111</option>
[<img src="https://images.seebug.org/upload/201412/02182831aefaf603a648ae335eaed754b52903ed.png" alt="5.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/02182831aefaf603a648ae335eaed754b52903ed.png)
[<img src="https://images.seebug.org/upload/201412/02182837250caf98461ce208278986186e5c9b2a.png" alt="6.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/02182837250caf98461ce208278986186e5c9b2a.png)
成功获取加密的相册内容!
### 漏洞证明:
问题出现在个人相册处:
首先我本地搭建个最新版的dz
1.先用test账号上传个图片进行权限设置 - 自己可见
[<img src="https://images.seebug.org/upload/201412/021824482c74a2cdf816fca2e0d2077586e71dc2.png" alt="1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/021824482c74a2cdf816fca2e0d2077586e71dc2.png)
[<img src="https://images.seebug.org/upload/201412/0218254634a91eee65347ad6091af54b05527aeb.png" alt="2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/0218254634a91eee65347ad6091af54b05527aeb.png)
2.用test111账号查看test账号的相册内容 显示加密
[<img src="https://images.seebug.org/upload/201412/021826277fe857f0a7d99afe814a8ac048cab093.png" alt="3.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/021826277fe857f0a7d99afe814a8ac048cab093.png)
[<img src="https://images.seebug.org/upload/201412/021827176d8624eb95e11b15d8ccd610d5f8a8c6.png" alt="4.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/021827176d8624eb95e11b15d8ccd610d5f8a8c6.png)
http://localhost/dz3.2_wwwroot/home.php?mod=space&uid=2&do=album&id=1
album&id=1 显示的是加密相册的id 记录下来
3.随便去发帖 - 选择图片 - 审查元素 - 将`<option value="改成对方加密相册的ID">111111</option>`
[<img src="https://images.seebug.org/upload/201412/02182831aefaf603a648ae335eaed754b52903ed.png" alt="5.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/02182831aefaf603a648ae335eaed754b52903ed.png)
[<img src="https://images.seebug.org/upload/201412/02182837250caf98461ce208278986186e5c9b2a.png" alt="6.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201412/02182837250caf98461ce208278986186e5c9b2a.png)
成功获取加密的相册内容!
暂无评论