Skip to content

PHP command execution exists in edit blog template in monstra 3.0.4 #468

@yanqian1993

Description

@yanqian1993

Vulnerability profile:
In edit blog template, we can control the website system by writing PHP executable code and running malicious code
Test environment: PHP version 5.6.2 +appach
Affected version
<=3.0.4
Vulnerability details:

  1. Use the administrative user to log in to the website: http://ip:port/monstra/admin/index.php?id=themes&action=edit_ template&filename=blog

2.Write PHP executable code in template content

image

3.Save the modified template content,visit:http://ip:port/monstra/blog
Get shell and control the website
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions