CVE-2019-10647: ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE)

CVE-2019-10647: ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE)-渗透云记 - 专注于网络安全与技术分享
CVE-2019-10647: ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE)
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2019-10647: Zzzcms ZZZPHP 1.6.3 – Remote PHP Code Execution (rce)

漏洞描述

ZZZCMS zzzphp v1.6.3 contains a remote code execution caused by lack of restrictions in inc/zzz_file.php, letting attackers execute arbitrary PHP code via a crafted URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter, exploit requires attacker to send malicious URL and server to serve PHP code as plain text.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享