Skip to content

Latest commit

 

History

History
23 lines (13 loc) · 1.09 KB

UCMS-RCE1.md

File metadata and controls

23 lines (13 loc) · 1.09 KB

There is an arbitrary file upload vulnerability (RCE) in the file management module in UCMS 1.6.

vendor: http://uuu.la/

UCMS 1.6 installation package: http://uuu.la/uploadfile/file/ucms_1.6.zip

After installation, log in to the background

Click File Management image

Click uploadfile image

Click to select the file, and after selecting the file ---> Click upload to upload to the "uploadfile directory"

image

image

We visit the shell.php file from the browser and upload it to the uploadfile directory of the website, and we find that the code has been executed

image