Seacms <=12.9 Any file download

> [Suggested description]

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary
commands via the admin_safe.php component.


> [VulnerabilityType Other]

Any file download


> [Vendor of Product]

https://www.seacms.com/download/


> [Affected Product Code Base]

seacms - <=12.9


> [Affected Component]

poc:https:http://127.0.0.1/seacms/upload/t9ljh/admin_safe.php?action=download&file=file relative path+file name


> [Attack Type]

Remote


> [Impact Escalation of Privileges]

true


> [Impact Information Disclosure]

true


> [Attack Vectors]

This is the address of the article where the vulnerability recurs:https://blog.csdn.net/DGS666/article/details/133795200?spm=1001.2014.3001.5501


> [Reference]

http://seacms.com
https://blog.csdn.net/DGS666/article/details/133795200?spm=1001.2014.3001.5501
https://www.seacms.com/download/​

Vulnerability description

By auditing the source code, in the admin_ In the safe.php file, a controllable variable was found and a vulnerability was found on line 94 of the code

Problem type

Any file download

Product

Seacms

Version

Seacms <= V12.9

Download address

​The latest version download address:https://www.seacms.com/download/
在这里插入图片描述

Vulnerability verification (漏洞验证)

在这里插入图片描述
Action=download, parameters obtained through get, controllable, and can be output as long as the file exists.

Enter the backend page:
在这里插入图片描述
poc = 127.0.0.1/seacms/upload/t9ljh/admin_safe.php?action=download&file=…/install/seacms.sql
在这里插入图片描述
Successfully downloaded seacms.sql file from the install folder.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
<form class="ant-form ant-form-horizontal"><div class="ant-row ant-form-item"style="row-gap: 0px;"><div class="ant-col ant-form-item-label"style="width: 100px;"><label for="form_item_licDetailType"class="ant-form-item-required"title="license类型">license类型<!----></label></div><div class="ant-col ant-form-item-control"><div class="ant-form-item-control-input"><div class="ant-form-item-control-input-content"><div class="ant-select ant-select-single ant-select-allow-clear ant-select-show-arrow"><!----><div class="ant-select-selector"><span class="ant-select-selection-search"><input type="search"id="form_item_licDetailType"autocomplete="off"class="ant-select-selection-search-input"role="combobox"aria-haspopup="listbox"aria-owns="form_item_licDetailType_list"aria-autocomplete="list"aria-controls="form_item_licDetailType_list"aria-activedescendant="form_item_licDetailType_list_0"readonly=""unselectable="on"style="opacity: 0;"aria-expanded="false"></span><!----><span class="ant-select-selection-placeholder">请选择</span></div><span class="ant-select-arrow"unselectable="on"aria-hidden="true"style="user-select: none;"><span role="img"aria-label="down"class="anticon anticon-down ant-select-suffix"><svg focusable="false"class=""data-icon="down"width="1em"height="1em"fill="currentColor"aria-hidden="true"viewBox="64 64 896 896"><path d="M884 256h-75c-5.1 0-9.9 2.5-12.9 6.6L512 654.2 227.9 262.6c-3-4.1-7.8-6.6-12.9-6.6h-75c-6.5 0-10.3 7.4-6.5 12.7l352.6 486.1c12.8 17.6 39 17.6 51.7 0l352.6-486.1c3.9-5.3.1-12.7-6.4-12.7z"></path></svg></span></span><!----></div></div><!----></div><!----><!----></div></div></form> 请进行selemiu 元素定位
07-13
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值