Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upload file to RCE in Zenario CMS 9.0.54156 #2

Closed
hieuminhnv opened this issue Oct 5, 2021 · 0 comments
Closed

Upload file to RCE in Zenario CMS 9.0.54156 #2

hieuminhnv opened this issue Oct 5, 2021 · 0 comments

Comments

@hieuminhnv
Copy link
Owner

Summary
hi team,
I found high Upload file to RCE.

Info
Zenario CMS 9.0.54156 last version
FireFox 92.0.1 (64-bit)
image

Steps

  1. Login to account http://xxx.xxx.x.x/admin.php?cID=1&cType=html
    image

  2. Choose Documents >> Upload documents
    image

  3. Use burpsuite and capture request file a.html
    image

  4. Click Edit document metadata >> use burpsuite to capture >> save
    image

  5. In value current_value, edit value html to php
    image

  6. Click Actions >> view public link
    image

7.Copy link to URL >> BOOM
image

Inpact :
An attacker could upload a dangerous executable file like a virus, malware, etc..
The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant