Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-26352 PoC — dotCMS 安全漏洞

Source
Associated Vulnerability
Title:dotCMS 安全漏洞 (CVE-2022-26352)
Description:dotCMS是美国dotCMS公司的一套内容管理系统(CMS)。该系统支持RSS订阅、博客、论坛等模块,并具有易于扩展和构建的特点。 dotCMS存在安全漏洞,该漏洞源于dotCMS不会清理临时文件名。攻击者利用该漏洞使用特制的请求,通过在dotCMS临时目录外写入的ContentResource API将文件发布到dotCMS。
Description
DotCMS management system contains an arbitrary file upload vulnerability via the /api/content/ path which can allow attackers to upload malicious Trojans to obtain server permissions.
File Snapshot

id: CVE-2022-26352 info: name: DotCMS - Arbitrary File Upload author: h1ei1 severity: critica ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.