当前位置:网站首页>phpok website vulnerability exploitation analysis
phpok website vulnerability exploitation analysis
2022-07-30 06:38:00 【[email protected]】
Environment description
Basic description
phpok is a set of enterprise website system developed with PHP+MySQL, and its 4.8.338 and 4.9.015 versions have arbitrary file upload vulnerabilities.
Vulnerability description
phpok is a set of enterprise website system developed with PHP+MySQL, its 4.8.338 and 4.9.015 versions have arbitrary file upload vulnerabilities, attackers can use the vulnerability to upload arbitrary files and obtain website permissions.
Bug fixes
Filter the upload type suffix; upgrade phpok to the latest version.
Install
Put the source code into the PHPstudy root directory www, and then install it locally.
Action
1. Select Tools----Attachment Classification Management
2. Select to create a resource category
(Add supported attachment types.php)
3. Select file resource management and uploaddocument.

4. The file is uploaded successfully, and there is a Trojan horse in the directory
5. Use ant sword or kitchen knife to connect
Success
版权声明
本文为[[email protected]]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/211/202207300539173142.html
边栏推荐
猜你喜欢

标准输入输出流(System.in,System.out)

SSTI靶场

Jackson 序列化失败问题-oracle数据返回类型找不到对应的Serializer

JDBC programming of MySQL database

uni-app: about custom components, easycom specs, uni_modules, etc.

使用Nodejs搭建Web Server(入门教程)

盲注、报错注入、宽字节注入、堆叠注入学习笔记

3 minutes to tell you how to become a hacker | Zero foundation to hacker introductory guide, you only need to master these five skills
CTF之misc-其他类型隐写

典型线程问题综合演示
随机推荐
C# WPF下限制TextBox只输入数字、小数点、删除等键
BaseDAO的抽取
npm run serve启动报错npm ERR Missing script “serve“
uncategorized SQLException; SQL state [null]; error code [0]; sql injection violation, syntax error
async/await用法详解
[PASECA2019]honey_shop
npm install和npm install --save
使用Context API维护全局状态
典型线程问题综合演示
Detailed MySQL-Explain
文件上传漏洞的绕过
【数仓】数据质量
DVWA安装教程(懂你的不懂·详细)
js 去除掉对象中的null,‘‘,[],{}
sqli-labs less3/4 Targeting Notes
[HCTF 2018]admin
awd总结
sqli-labs靶场 SQL注入学习 Less-1
php-fpm
【Spark】Spark 高频面试题英语版(1)