当前位置:网站首页>Vulhub vulnerability recurrence 69_ Tiki Wiki
Vulhub vulnerability recurrence 69_ Tiki Wiki
2022-07-06 05:17:00 【Revenge_ scan】
CVE-2020-15906_Tiki Wiki CMS Groupware Authentication bypass vulnerability
Vulnerability Details
Tiki Wiki CMS Groupware Or for short Tiki( Originally known as TikiWiki) Is a free and open source based on Wiki Content management system and online office suite . In the following versions 21.2, 20.4, 19.3, 18.7, 17.3, 16.4 There is a logical error before , The administrator account was exploded 60 It will be locked more than times , At this time, you can log in to the background as an administrator by using a blank password .
Reference link :
- https://info.tiki.org/article473-Security-Releases-of-all-Tiki-versions-since-16-3
- https://github.com/S1lkys/CVE-2020-15906
-http://packetstormsecurity.com/files/159663/Tiki-Wiki-CMS-Groupware-21.1-Authentication-Bypass.html
- https://srcincite.io/pocs/cve-2021-26119.py.txt
Vulnerability environment
shooting range :192.168.4.10_ubuntu
Execute the following command to start a Tiki Wiki CMS 21.1:
#docker-compose up -d
After the environment starts , visit `http://your-ip:8080` You can see its welcome page .
Loophole recurrence
We can use <https://srcincite.io/pocs/cve-2021-26119.py.txt> Medium [POC](poc.py) To reproduce . The POC First use CVE-2020-15906 Bypass Authentication , Get administrator privileges ; Reuse Smarty Sandbox bypass vulnerability of (CVE-2021-26119) Execute arbitrary commands in the background :
#Python3 poc.py your-ip:8080 / id
Be careful , Affected by the principle of vulnerability , Execute this POC It will cause the administrator account to be locked .
边栏推荐
- [lgr-109] Luogu may race II & windy round 6
- 【LGR-109】洛谷 5 月月赛 II & Windy Round 6
- The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
- 用StopWatch 统计代码耗时
- UCF(2022暑期团队赛一)
- GAMES202-WebGL中shader的编译和连接(了解向)
- February 12 relativelayout
- Driver development - hellowdm driver
- A little knowledge of CPU, disk and memory
- 关于Unity Inspector上的一些常用技巧,一般用于编辑器扩展或者其他
猜你喜欢
Postman manage test cases
【LeetCode】18、四数之和
Talking about the type and function of lens filter
Compilation and connection of shader in games202 webgl (learn from)
趋势前沿 | 达摩院语音 AI 最新技术大全
F12 solve the problem that web pages cannot be copied
Rce code and Command Execution Vulnerability
Crazy God said redis notes
Idea one key guide package
Huawei equipment is configured with OSPF and BFD linkage
随机推荐
2021robocom robot developer competition (Preliminary)
[lgr-109] Luogu may race II & windy round 6
Force buckle 1189 Maximum number of "balloons"
Driver development - hellowdm driver
Modbus protocol communication exception
[leetcode16] the sum of the nearest three numbers (double pointer)
[effective Objective-C] - memory management
TCP three handshakes you need to know
The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
[buuctf.reverse] 159_[watevrCTF 2019]Watshell
[mask requirements of OSPF and Isis in multi access network]
Raspberry pie 3.5-inch white screen display connection
Configuration file converted from Excel to Lua
Steady, 35K, byte business data analysis post
Postman manage test cases
Leetcode 186 Flip the word II in the string (2022.07.05)
Select knowledge points of structure
Basic knowledge and examples of binary tree
The video in win10 computer system does not display thumbnails
The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower