YxCMS v1.21任意文件写入漏洞

YxCMS v1.21任意文件写入漏洞

靶机:172.168.83.154

kali:172.168.30.45

常规扫描

image-20210121144650812

image-20210121144719704

扫出来后台管理界面地址

http://172.168.83.154/index.php?r=admin/index/login

后台弱口令

image-20210121155927350

http://172.168.83.154/index.php?r=admin/set/tpadd&Mname=default

image-20210121220633831

image-20210121220601470

http://172.168.83.154/protected/apps/default/view/default/shell.php

image-20210121162528461

image-20210121170319361image-20210121170330599

image-20210121170428296

ms17-010 一键打穿

image-20210121153943080

image-20210121153310355

参考

[1] https://www.freebuf.com/column/184853.html

posted @ 2021-01-21 22:11  vivovox  阅读(1620)  评论(0编辑  收藏  举报