Skip to content

I found that at /admin/template_wap.php, I was allowed to log in and write arbitrary files(Login required) #5

@H9dawn

Description

@H9dawn

Of course, you have to log in to the background first .Don't forget that dawn is my modified background address. It was originally admin

At "dawn\template_wap.php", there is a sensitive function to write to the file:

1

We can control the filename and content, We have nothing to do with this "escape_stripslashes".

The method to call this function is the same as above. We construct the data package:

2

3

4

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions