某通用在线考试系统可getshell、注册管理员等

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 某通用在线考试系统可getshell、注册管理员等 ### 详细说明: 上海天柏信息科技有限公司的系统: 测试地址:http://www.timber2005.com/Product_sy.html demo: http://exam1.timber2005.com/login.aspx 首先注册一个普通账号: [<img src="https://images.seebug.org/upload/201409/14162138d5881133c4e95f98b25650a20c465267.jpg" alt="21.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/14162138d5881133c4e95f98b25650a20c465267.jpg) 然后登陆: [<img src="https://images.seebug.org/upload/201409/141622482d992d1840ffba7a4a48fb7ceb3c3a7e.jpg" alt="22.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/141622482d992d1840ffba7a4a48fb7ceb3c3a7e.jpg) 之后直接访问: http://exam1.timber2005.com/system/system_config.aspx [<img src="https://images.seebug.org/upload/201409/141625110d99a02f23a89571cb9a60efd021a5db.jpg" alt="23.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201409/141625110d99a02f23a89571cb9a60efd021a5db.jpg)...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息