目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1000

100.0%

CVE-2024-9916 PoC — UTCMS 操作系统命令注入漏洞

来源
关联漏洞
标题:UTCMS 操作系统命令注入漏洞 (CVE-2024-9916)
Description:UTCMS是usualtool个人开发者的一个基于 UT 框架构建的内容管理系统。 UTCMS V9存在操作系统命令注入漏洞,该漏洞源于对参数的处理不当,导致os命令注入。
Description
A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection.The attack may be launched remotely. The exploit has been disclosed to the public and may be used.The vendor was contacted early about this disclosure but did not respond in any way.
文件快照

id: CVE-2024-9916 info: name: HuangDou UTCMS V9 - OS Command Injection author: iamnoooob,pdrese ...
神龙机器人已为您缓存
备注
    1. 建议优先通过来源进行访问。
    2. 如果因为来源失效或无法访问,请发送邮件到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
    3. 神龙已为您对 POC 代码进行快照,为了长期维护,请考虑为本地 POC 付费/捐赠,感谢您的支持。