POC/wpoc/Emlog/emlog后台插件任意文件上传(CVE-2024-33752).md
eeeeeeeeee-code 06c8413e64 first commit
2025-03-04 23:12:57 +08:00

29 lines
597 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

## emlog后台插件任意文件上传(CVE-2024-33752)
emlog 是一款基于 PHP 和 MySQL 的功能强大的博客及 CMS 建站系统,追求快速、稳定、简单、舒适的建站体验。
## fofa
```
app="EMLOG"
```
## poc
1.制作插件zipzip内必须有一个文件夹
![image-20240521200900076](./assets/202405212009117.png)
2.点击“插件-安装插件-选择文件”上传制作好的zip文件
![image-20240521201022196](./assets/202405212010276.png)
3.然后访问下面链接成功getshell。
```
http://192.168.243.175/content/plugins/test/test.php
```