indexhibit cms v2.1.5 存在重装漏洞并导致getshell(CVE-2019-16314)

2021-01-19 indexhibit cms PoC No

Description

Indexhibit2.16以下版本未对重装条件做校验,若配置不严格安装cms后未删除install.php,可以直接在/ndxzstudio/install.php?p=2重装系统,攻击者可以利用该漏洞进入系统后台,而在2.15版本中可以编辑php文件,导致getshell。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities