LaikeTui icon indicating copy to clipboard operation
LaikeTui copied to clipboard

There is a file upload getshell vulnerability in the background system/actions/payAction.class.php

Open S2eTo opened this issue 2 years ago • 0 comments

File Path LKT/webapp/modules/system/actions/payAction.class.php#L63

After uploading as a .zip file, the archive will be decompressed. You can gain system control by putting the php webshell file in the compressed package

image

Upload a compressed package file with webshell below

image

Successfully accessed the shell file under LKT/webapp/lib/cert

image

S2eTo avatar Nov 03 '22 15:11 S2eTo