Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-0518 PoC — LotusCMS Fraise core/lib/router.php目录遍历漏洞

Source
Associated Vulnerability
Title:LotusCMS Fraise core/lib/router.php目录遍历漏洞 (CVE-2011-0518)
Description:当magic_quotes_gpc禁用时,LotusCMS Fraise 3.0中的core/lib/router.php中存在目录遍历漏洞。远程攻击者可以借助向index.php传递的system参数包含并执行任意本地文件。
Description
LotusCMS 3.0 is susceptible to remote code execution via the Router () function. This is done by embedding PHP code in the 'page' parameter, which will be passed to a eval call and allow remote code execution.
File Snapshot

id: CVE-2011-0518 info: name: LotusCMS 3.0 - Remote Code Execution author: pikpikcu severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.