Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-11586 PoC — dayrui FineCms 安全漏洞

Source
Associated Vulnerability
Title:dayrui FineCms 安全漏洞 (CVE-2017-11586)
Description:Dayrui FineCms是中国天睿(Dayrui)程序设计团队发布的一套使用MVC架构和PDO数据库接口开发的内容管理系统(CMS)。 dayrui FineCms 5.0.9版本中存在安全漏洞。攻击者可利用该漏洞将用户重定向到任意的URL。
Description
FineCMS 5.0.9 contains an open redirect vulnerability via the url parameter in a sync action. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
File Snapshot

id: CVE-2017-11586 info: name: FineCMS <5.0.9 - Open Redirect author: 0x_Akoko severity: medi ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.