2021-08-02 14:45:40 +08:00
..
2021-08-02 14:45:40 +08:00
2021-08-02 14:45:40 +08:00

Klog Server Unauth RCE(CVE-2020-35729)

The 'authenticate.php' file uses the 'user' HTTP POST parameter in a call to the 'shell_exec()' PHP function without appropriate input validation,allowing arbitrary command execution as the apache user.

Affected Version: ≤2.4.1

FOFA query rule: title="KLog Server" && body="authenticate.php"

Demo