POC详情: 4dbe4d7b07b48c32177bc470f39dba6f81f0d377

来源
关联漏洞
标题: UTCMS 操作系统命令注入漏洞 (CVE-2024-9916)
描述:UTCMS是usualtool个人开发者的一个基于 UT 框架构建的内容管理系统。 UTCMS V9存在操作系统命令注入漏洞,该漏洞源于对参数的处理不当,导致os命令注入。
描述
A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection.The attack may be launched remotely. The exploit has been disclosed to the public and may be used.The vendor was contacted early about this disclosure but did not respond in any way.
文件快照

id: CVE-2024-9916 info: name: HuangDou UTCMS V9 - OS Command Injection author: iamnoooob,pdrese ...
神龙机器人已为您缓存
备注
    1. 建议优先通过来源进行访问。
    2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
    3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。