menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right All_wiki chevron_right yougar0.github.io(基于零组公开漏洞库 + PeiQi文库的一些漏洞)-20210715 chevron_right Web安全 chevron_right Typesetter CMS chevron_right Typesetter CMS任意文件上传.md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    Typesetter CMS任意文件上传.md
    819 B / 2021-04-21 09:23:46
        # Typesetter CMS任意文件上传
    
    - Steps to reproduce
        1- As admin go to Content menu and click on Uploaded files
        2- Inside the try to upload a .php file, and
        3- try to upload a .php file directly, check that it is not possible.
        4- Take the same .php file and place it in a .zip and upload it.
        5- Extract through functionality and open the .php file
        **Obs**: A strange behavior was that, after extracting the PHP file in functionality, it is seen as HTML.
    
    - PoC
        ==> Executing Commands
    
        
    
        ![poc_01](resource/Typesetter%20CMS%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0/media/93630451-7595a580-f9c0-11ea-9166-30d2ede2535a.gif)
    
    ![test](resource/Typesetter%20CMS%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0/media/93628723-6d883680-f9bd-11ea-9d89-610565c43878.gif)
    
    links
    file_download