Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Update IDOR2.java
admin.无法登录
另外建议让zhangwei和admin都可以登录系统,不要写死只有admin登录
这样就可以很好的对比zhangwei不能访问这个safe/admin的url,对比越权漏洞
  • Loading branch information
k4n5ha0 authored Jan 3, 2023
commit 60c821134a0f92cfb3a10f1212be10ae92bd565f
2 changes: 1 addition & 1 deletion src/main/java/com/best/hello/controller/IDOR/IDOR2.java
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ public String vul() {
// 只允许admin用户可以访问管理页面
@GetMapping(value = "/safe/admin")
public String safe(HttpSession session) {
if (session.getAttribute("LoginUser").equals("admin.")) {
if (session.getAttribute("LoginUser").equals("admin")) {
return "idoradmin";
} else {
return "commons/403";
Expand Down