havok89 / Hoosk

Hoosk Codeigniter CMS

Home Page:http://hoosk.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Hoosk v1.8 has an arbitrary file upload vulnerability

pwdid opened this issue · comments

commented

Vulnerability exists in /attachments routing

After logging in to the background, there is an interface for uploading arbitrary files. You can upload php files by building network packages to obtain webshell

image-20221011101029899
image-20221011101052588