we can get the source code from http://www.huakecms.com/
![](https://img.haomeiwen.com/i11234137/7b9105063f8cf602.png)
![](https://img.haomeiwen.com/i11234137/69688d920bb84072.png)
the issues in the /admin/cms_admin.php that you can Reset admin's password to 123456 without logging in
![](https://img.haomeiwen.com/i11234137/5bae47b05b79529c.png)
so let's do this
![](https://img.haomeiwen.com/i11234137/5834cca42fb7f740.png)
we can see the password has been changed in mysql
![](https://img.haomeiwen.com/i11234137/7c3b90171394a964.png)
and then we can log as the as admin
网友评论