Srun3000计费系统无限制多处任意命令执行getshell

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: Srun3000计费系统无限制任意命令执行getshell ### 详细说明: 文件: /en_us/rad_online.php srun3/web/online.php 4-76行 srun3/web/rad_online.php 4-76行 ``` if($_POST["action"]=="dm") { $cmd = "/srun3/bin/rad_drop -sdm ".$_POST["sid"]; if($fp=popen($cmd, "r")) { $con = fread($fp, 128); pclose($fp); } $con = str_replace( "\n", " ", $con); echo $con; exit; } else if($_POST["action"]=="dm1") { $cmd = "/srun3/bin/rad_drop -sdm ".$_POST["sid"]; if($fp=popen($cmd, "r")) { $con = fread($fp, 128); pclose($fp); } $con = str_replace( "\n", " ", $con); if(strstr($con, "1")) { $cmd = "/srun3/bin/set_user mac_auth ".$_POST["username"]." ".$_POST["mac"]." stop"; if($fp=popen($cmd, "r")) { //$con = fread($fp, 128); pclose($fp); } } echo $con; exit; } $username=trim($_POST["username"]); $password=trim($_POST["password"]); //echo $username.",".$password; //校验用户 if($username != "" && $password != "") { $cmd = "/srun3/bin/show_user ".$username. "|grep user_password_ori"; echo $username; if($fp=popen($cmd, "r")) { $con...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息