当前位置:网站首页>Vulhub vulnerability recurrence 69_ Tiki Wiki
Vulhub vulnerability recurrence 69_ Tiki Wiki
2022-07-06 05:17:00 【Revenge_ scan】
CVE-2020-15906_Tiki Wiki CMS Groupware Authentication bypass vulnerability
Vulnerability Details
Tiki Wiki CMS Groupware Or for short Tiki( Originally known as TikiWiki) Is a free and open source based on Wiki Content management system and online office suite . In the following versions 21.2, 20.4, 19.3, 18.7, 17.3, 16.4 There is a logical error before , The administrator account was exploded 60 It will be locked more than times , At this time, you can log in to the background as an administrator by using a blank password .
Reference link :
- https://info.tiki.org/article473-Security-Releases-of-all-Tiki-versions-since-16-3
- https://github.com/S1lkys/CVE-2020-15906
-http://packetstormsecurity.com/files/159663/Tiki-Wiki-CMS-Groupware-21.1-Authentication-Bypass.html
- https://srcincite.io/pocs/cve-2021-26119.py.txt
Vulnerability environment
shooting range :192.168.4.10_ubuntu
Execute the following command to start a Tiki Wiki CMS 21.1:
#docker-compose up -d
After the environment starts , visit `http://your-ip:8080` You can see its welcome page .
Loophole recurrence
We can use <https://srcincite.io/pocs/cve-2021-26119.py.txt> Medium [POC](poc.py) To reproduce . The POC First use CVE-2020-15906 Bypass Authentication , Get administrator privileges ; Reuse Smarty Sandbox bypass vulnerability of (CVE-2021-26119) Execute arbitrary commands in the background :
#Python3 poc.py your-ip:8080 / id
Be careful , Affected by the principle of vulnerability , Execute this POC It will cause the administrator account to be locked .
边栏推荐
- The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
- Huawei equipment is configured with OSPF and BFD linkage
- 2021 robocom world robot developer competition - undergraduate group (semi-finals)
- UCF (2022 summer team competition I)
- [mask requirements of OSPF and Isis in multi access network]
- [noip2009 popularization group] score line delimitation
- Yyds dry inventory SSH Remote Connection introduction
- Mysql高级篇学习总结9:创建索引、删除索引、降序索引、隐藏索引
- The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
- The video in win10 computer system does not display thumbnails
猜你喜欢
随机推荐
集合详解之 Collection + 面试题
[leetcode] 18. Sum of four numbers
你需要知道的 TCP 三次握手
Yyds dry inventory SSH Remote Connection introduction
Drive development - the first helloddk
Upload nestjs configuration files, configure the use of middleware and pipelines
Acwing week 58
[buuctf.reverse] 159_ [watevrCTF 2019]Watshell
行业专网对比公网,优势在哪儿?能满足什么特定要求?
Three.js学习-光照和阴影(了解向)
图数据库ONgDB Release v-1.0.3
Leetcode 186 Flip the word II in the string (2022.07.05)
指针经典笔试题
Sliding window problem review
[leetcode16] the sum of the nearest three numbers (double pointer)
Rce code and Command Execution Vulnerability
Idea one key guide package
Postman Association
Unity gets the width and height of Sprite
指針經典筆試題