目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2020-29607 PoC — Pluck 代码问题漏洞

来源
关联漏洞
标题: Pluck 代码问题漏洞 (CVE-2020-29607)
Description:Pluck是一套使用PHP语言开发的内容管理系统(CMS)。 Pluck CMS 4.7.13 之前版本存在代码问题漏洞,该漏洞源于一个文件上传限制绕过漏洞允许一个管理员特权用户通过“管理文件”功能访问主机,这可能导致远程代码执行。
Description
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
介绍
# CVE-2020-29607-Exploit
### Exploit Title: Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)

## CVE description:
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
  - https://nvd.nist.gov/vuln/detail/CVE-2020-29607

## ExploitDB:
  - https://www.exploit-db.com/exploits/49909

## Exploit Description:
An authenticated attack can upload a .phar file by using http://IP/admin.php?action=files to gain a webshell.
- Vendor Homepage: Vendor Homepage: https://github.com/pluck-cms/pluck
- Software Link: https://github.com/pluck-cms/pluck/releases/tag/4.7.13
- Version: 4.7.13
- Tested on Xubuntu 20.04

## Usage:
python3 exploit.py Target_IP Target_Port Username



- 🕊️ Twitter: [@0xAbbarhSF](https://twitter.com/0xAbbarhSF)
[![Tweet](https://img.shields.io/twitter/url/http/0xAbbarhSF.svg?style=social)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fdeveloper.twitter.com%2Fen%2Fdocs%2Ftwitter-for-websites%2Ftweet-button%2Foverview&ref_src=twsrc%5Etfw&text=CMS-Xploiter%20-%20Automated%20Pentest%20Recon%20Scanner%20%400xAbbarhSD&tw_p=tweetbutton&url=https%3A%2F%2Fgithub.com%2F0xAbbarhSF%)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →