Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-2744 PoC — Chyrp目录遍历漏洞

Source
Associated Vulnerability
Title:Chyrp目录遍历漏洞 (CVE-2011-2744)
Description:Chyrp是一款开源的基于PHP和MySQL的轻量级博客(Blog)引擎。 Chyrp 2.1及之前版本中存在目录遍历漏洞。借助action参数向index.php传递的输入在被用于包含文件之前没有经过正确验证,远程攻击者可借助目录遍历序列和URL编码的NULL字节包含并执行任意本地文件。
Description
A directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI.
File Snapshot

id: CVE-2011-2744 info: name: Chyrp 2.x - Local File Inclusion author: daffainfo severity: me ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.