Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2020-25540 PoC — ThinkAdmin 路径遍历漏洞

Source
Associated Vulnerability
Title: ThinkAdmin 路径遍历漏洞 (CVE-2020-25540)
Description:ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET request encode parameter.
Description
ThinkAdmin CVE-2020-25540 poc
Readme
# CVE-2020-25540
ThinkAdmin CVE-2020-25540 poc

由于目录穿越那个洞太鸡肋,就只写了文件读取功能,带哥们轻喷,多多指教,感激不尽。
逻辑参考php源码,关键是加密方式,看一看就懂了

use age:

python3 poc.py -t \<IP\> -c \<command\>
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →