Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

exist is an arbitrary file delete vulnerability #12

Open
win1498419293 opened this issue Dec 11, 2021 · 0 comments
Open

exist is an arbitrary file delete vulnerability #12

win1498419293 opened this issue Dec 11, 2021 · 0 comments

Comments

@win1498419293
Copy link

1.The location of the vulnerability is in taocms\include\Model\file.php from line 60 to line 72 and line 64 to determine whether the incoming folder is empty. Delete the empty folder. If it is not empty, it will not be deleted, but the incoming folder will not be deleted. File filtering.. And / although it is not possible to delete non-empty folders, but you can delete any file
image
2.Create a new file on disk d to delete it
image
3.Enter the background to find the file management function and find a file to delete
image
image
4.1.txt in the D drive directory and successfully deleted, it proves that you can indeed use ../ to jump to the directory to operate any file, but you need to pay attention to the folder can only delete empty folders
image

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant