当前位置:网站首页>Vulhub vulnerability recurrence 69_ Tiki Wiki
Vulhub vulnerability recurrence 69_ Tiki Wiki
2022-07-06 05:17:00 【Revenge_ scan】
CVE-2020-15906_Tiki Wiki CMS Groupware Authentication bypass vulnerability
Vulnerability Details
Tiki Wiki CMS Groupware Or for short Tiki( Originally known as TikiWiki) Is a free and open source based on Wiki Content management system and online office suite . In the following versions 21.2, 20.4, 19.3, 18.7, 17.3, 16.4 There is a logical error before , The administrator account was exploded 60 It will be locked more than times , At this time, you can log in to the background as an administrator by using a blank password .
Reference link :
- https://info.tiki.org/article473-Security-Releases-of-all-Tiki-versions-since-16-3
- https://github.com/S1lkys/CVE-2020-15906
-http://packetstormsecurity.com/files/159663/Tiki-Wiki-CMS-Groupware-21.1-Authentication-Bypass.html
- https://srcincite.io/pocs/cve-2021-26119.py.txt
Vulnerability environment
shooting range :192.168.4.10_ubuntu
Execute the following command to start a Tiki Wiki CMS 21.1:
#docker-compose up -d
After the environment starts , visit `http://your-ip:8080` You can see its welcome page .

Loophole recurrence
We can use <https://srcincite.io/pocs/cve-2021-26119.py.txt> Medium [POC](poc.py) To reproduce . The POC First use CVE-2020-15906 Bypass Authentication , Get administrator privileges ; Reuse Smarty Sandbox bypass vulnerability of (CVE-2021-26119) Execute arbitrary commands in the background :
#Python3 poc.py your-ip:8080 / id

Be careful , Affected by the principle of vulnerability , Execute this POC It will cause the administrator account to be locked .
边栏推荐
- 剑指 Offer II 039. 直方图最大矩形面积
- Some common skills on unity inspector are generally used for editor extension or others
- [leetcode16] the sum of the nearest three numbers (double pointer)
- Codeforces Round #804 (Div. 2)
- 2022半年总结
- 注释、接续、转义等符号
- Force buckle 1189 Maximum number of "balloons"
- Please wait while Jenkins is getting ready to work
- Nestjs配置文件上传, 配置中间件以及管道的使用
- Pointer classic written test questions
猜你喜欢

Postman pre script - global variables and environment variables
![[effective Objective-C] - memory management](/img/1e/611aa998486bbac76ac103c3091794.jpg)
[effective Objective-C] - memory management

行业专网对比公网,优势在哪儿?能满足什么特定要求?

Class inheritance in yyds dry inventory C

Modbus protocol communication exception

Three methods of Oracle two table Association update

Notes, continuation, escape and other symbols

浅谈镜头滤镜的类型及作用

Nacos - TC Construction of High available seata (02)

Yolov5 tensorrt acceleration
随机推荐
从0到1建设智能灰度数据体系:以vivo游戏中心为例
【LGR-109】洛谷 5 月月赛 II & Windy Round 6
HAC集群修改管理员用户密码
nacos-高可用seata之TC搭建(02)
Promotion hung up! The leader said it wasn't my poor skills
Fiddler installed the certificate, or prompted that the certificate is invalid
【LeetCode】18、四数之和
2022半年总结
Unity gets the width and height of Sprite
jdbc使用call调用存储过程报错
SQLite queries the maximum value and returns the whole row of data
F12 solve the problem that web pages cannot be copied
Codeforces Round #804 (Div. 2) Editorial(A-B)
2021 robocom world robot developer competition - undergraduate group (semi-finals)
Modbus协议通信异常
Rce code and Command Execution Vulnerability
Codeforces Round #804 (Div. 2)
趋势前沿 | 达摩院语音 AI 最新技术大全
Modbus protocol communication exception
Three. JS learning - light and shadow (understanding)