taocms
taocms copied to clipboard
taoCMS is an incredible tiny CMS( Content Management System) , writen in PHP and support MySQL/Sqlite as the database(MIT License)
data:image/s3,"s3://crabby-images/ea52b/ea52bcde4783bb1fb01d15cfd3b1d39ffd0759a5" alt="image" ``` GET /admin/admin.php?action=cms&id=1)or(sleep(5))--+&ctrl=del HTTP/1.1 Host: taocms.test Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Referer: http://taocms.test/admin/admin.php?action=admin&ctrl=lists Accept-Encoding: gzip, deflate Accept-Language:...
## analysis The location of the vulnerability is line 33 in taocms\include\Model\Article.php, and the incoming sql statement in the update() method does not use intval to process id,and Link.php extends...
## poc After login as admin,file manager and downloadfunction data:image/s3,"s3://crabby-images/0e4aa/0e4aa78257de8efcc7ed06fbbf98e0aeba5fb647" alt="image" after change path param can read arbitrary file data:image/s3,"s3://crabby-images/03404/03404e844aaff483e26e6738fef0f5a670c8cabd" alt="image" ## analysis location:include/File.php data:image/s3,"s3://crabby-images/56a38/56a3843e146ba7795bdfd010812803da3248c1da" alt="image" data:image/s3,"s3://crabby-images/17de8/17de86bb11f8da1b3733e6f7b41778bd66c4a6e3" alt="image" we can use ../ to traverse...
1.The location of the vulnerability is in taocms\include\Model\file.php from line 60 to line 72 and line 64 to determine whether the incoming folder is empty. Delete the empty folder. If...
1.The location of the vulnerability is line 59 in taocms\include\Model\Cms.php, and the incoming sql statement in the update() method does not use intval to process id The location of the...
First, we enter the background and use the administrator admin we created: data:image/s3,"s3://crabby-images/01fe4/01fe4eb2b05805a381537880c964bb04bcadb320" alt="image-20211210101406045" Let's click "file management" on the left: data:image/s3,"s3://crabby-images/d49a8/d49a8f0d325cb5b84fe8c1f84ad9c8cecc217716" alt="image-20211210102337699" Then use Burp Suite and click Download to grab...
First, we enter the background and use the column administrator admin we created: data:image/s3,"s3://crabby-images/e3a0b/e3a0b13129166aedea93918b5adb08ea7cd67f20" alt="image" Let's click "add article" on the left: data:image/s3,"s3://crabby-images/b6a17/b6a17bafec980bf838e9caa03410a41a0532d5ca" alt="image" Insert xss payload at the title : Return...
Log in to the background as the default account admin. data:image/s3,"s3://crabby-images/30e79/30e79d408f9101d88c8abd9de0f12086c8cb5983" alt="1" We click in order and grab packets: data:image/s3,"s3://crabby-images/d3aef/d3aef104f16b63c859dbc4c896eacdded2656934" alt="2" data:image/s3,"s3://crabby-images/c38af/c38afc13b1d7c8e3860acff71b8916ae0e0f829a" alt="3" data:image/s3,"s3://crabby-images/6b129/6b129fe7daa08fb659934722b1610e0d48961019" alt="4" There is a time-based blind SQL injection vulnerability in...
First, construct our POC and put it on our website, the url is `http://test.com/id-1502.html`. The POC is as follows: ```html Test title Testcontent-1 Testcontent-2 ``` Then log in to the...