Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

修复 console 模式下的一处 bug。use poc1->use poc2->use poc1 使用的是poc2的脚本 #61

Merged
merged 1 commit into from
Jul 5, 2019

Conversation

hawoosec
Copy link

@hawoosec hawoosec commented Jul 5, 2019

修复前

Pocsuite3 > use pocs/ecshop_rce
Pocsuite3 (pocs/ecshop_rce) > use pocs/drupalgeddon2
Pocsuite3 (pocs/drupalgeddon2) > use pocs/ecshop_rce
Pocsuite3 (pocs/ecshop_rce) > show info

name                 Drupal core Remote Code Execution
version              1.0
author               ['seebug']
vulDate              2018-03-08
createDate           2018-04-12
updateDate           2018-04-13
references           ['https://www.seebug.org/vuldb/ssvid-97207']
appName              Drupal
vulType              Romote Code Execution
desc

修复后

Pocsuite3 (pocs/ecshop_rce) > use pocs/ecshop_rce
Pocsuite3 (pocs/ecshop_rce) > use pocs/drupalgeddon2
Pocsuite3 (pocs/drupalgeddon2) > use pocs/ecshop_rce
Pocsuite3 (pocs/ecshop_rce) > show info

name                 Ecshop 2.x/3.x Remote Code Execution
version              3.0
author               ['seebug']
vulDate              2018-06-14
createDate           2018-06-14
updateDate           2018-06-14
references           ['https://www.seebug.org/vuldb/ssvid-97343']
appName              ECSHOP
appVersion           2.x,3.x
vulType              Romote Code Execution
desc                 近日,Ecshop爆出全版本SQL注入及任意代码执行漏洞,受影响的版本有:Ecshop 2.x,Ecshop 3.x-3.6.0

@boy-hack boy-hack merged commit 1b65765 into knownsec:master Jul 5, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants