Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-16836 PoC — Rubedo theme组件路径遍历漏洞

Source
Associated Vulnerability
Title:Rubedo theme组件路径遍历漏洞 (CVE-2018-16836)
Description:Rubedo是一套内容管理系统。theme是其中的一个主题组件。 Rubedo 3.4.0及之前版本中的theme组件存在路径遍历漏洞。攻击者可利用该漏洞读取并执行该服务根目录之外的任意文件。
Description
Rubedo CMS through 3.4.0 contains a directory traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.
File Snapshot

id: CVE-2018-16836 info: name: Rubedo CMS <=3.4.0 - Directory Traversal author: 0x_Akoko seve ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.