跳转到帖子

游客您好,欢迎来到黑客世界论坛!您可以在这里进行注册。

赤队小组-代号1949(原CHT攻防小组)在这个瞬息万变的网络时代,我们保持初心,创造最好的社区来共同交流网络技术。您可以在论坛获取黑客攻防技巧与知识,您也可以加入我们的Telegram交流群 共同实时探讨交流。论坛禁止各种广告,请注册用户查看我们的使用与隐私策略,谢谢您的配合。小组成员可以获取论坛隐藏内容!

TheHackerWorld官方

Redaxo CMS Mediapool Addon < 5.5.1 - Arbitrary File Upload

精选回复

发布于
# Exploit Title: Redaxo CMS Mediapool Addon < 5.5.1 - Arbitrary File Upload
# Date: 2018-06-13
# Exploit Author: mn@HackerWerkstatt
# Vendor Homepage: https://redaxo.org
# Software Link: https://redaxo.org/download/redaxo/5.5.1.zip
# Version: 5.5.1 and older
# Tested on: LinuxMint
# More: Login required

### PoC ###

In the REDAXO CMS under version 5.6.0 the mediapool addon is vuln. Users who have an user-account, like editor, 
can use the mediapool to upload files. The mediapool addon under version 2.4.0 uses a blacklist for fileupload. 
For users it isn't possible upload files named: php, php4, php5, php6 or php7.

But, if you name the files like php71 or php53 the blacklist-function ignore this and upload of shellcode-file is possible.

https://example.com/redaxo/index.php?page=mediapool/media

### Fixed in mediapool 2.4.0 and Redaxo CMS 5.6.0
### reported: 08.03.2018
### fixed: 08.06.2018
            

创建帐户或登录后发表意见

最近浏览 0

  • 没有会员查看此页面。