CMSimple 5.15 - Remote Code Execution (RCE)

admin 2024年6月11日08:43:56评论13 views字数 569阅读1分53秒阅读模式

RCE

01CMSimple 5.15 RCE

POC:

# Exploit Title: CMSimple 5.15 - Remote Command Execution# Date: 04/28/2024# Exploit Author: Ahmet Ümit BAYRAM# Vendor Homepage: https://www.cmsimple.org# Software Link: https://www.cmsimple.org/downloads_cmsimple50/CMSimple_5-15.zip# Version: latest# Tested on: MacOS

# Log in to SimpleCMS.# Go to Settings > CMS# Append ",php" to the end of the Extensions_userfiles field and save it.# Navigate to Files > Media# Select and upload shell.php# Your shell is ready: https://{url}/userfiles/media/shell.php

链接:

https://www.exploit-db.com/exploits/52040

原文始发于微信公众号(道玄网安驿站):CMSimple 5.15 - Remote Code Execution (RCE)

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2024年6月11日08:43:56
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   CMSimple 5.15 - Remote Code Execution (RCE)https://cn-sec.com/archives/2812858.html

发表评论

匿名网友 填写信息