Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-9916 PoC — UTCMS 操作系统命令注入漏洞

Source
Associated Vulnerability
Title:UTCMS 操作系统命令注入漏洞 (CVE-2024-9916)
Description:UTCMS是usualtool个人开发者的一个基于 UT 框架构建的内容管理系统。 UTCMS V9存在操作系统命令注入漏洞,该漏洞源于对参数的处理不当,导致os命令注入。
Description
A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection.The attack may be launched remotely. The exploit has been disclosed to the public and may be used.The vendor was contacted early about this disclosure but did not respond in any way.
File Snapshot

id: CVE-2024-9916 info: name: HuangDou UTCMS V9 - OS Command Injection author: iamnoooob,pdrese ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.