17 Star 49 Fork 17

koyshe / phpshe

 / 详情

I found a vulnerability that can getshell

待办的
创建于  
2018-10-18 09:32

I found that the latest version can delete files arbitrarily in the background, so you can delete the install.lock file and use reload to getshell.

  1. First in the background
    后台
    poc

  2. Then install.lock will be deleted

  3. Then we go to reload and get the shell
    structure poc

';phpinfo();'

getshell

certificate

评论 (1)

p0desta。 创建了任务

这不是在wuyun上有过的也可以提交cve啊

登录 后才可以发表评论

状态
负责人
里程碑
Pull Requests
关联的 Pull Requests 被合并后可能会关闭此 issue
分支
开始日期   -   截止日期
-
置顶选项
优先级
参与者(2)
PHP
1
https://gitee.com/koyshe/phpshe.git
git@gitee.com:koyshe/phpshe.git
koyshe
phpshe
phpshe

搜索帮助