Atom-CMS-2.0---File-Upload-Remote-Code-Execution-Un-Authenticated-
Remote Code Execution (RCE)
- Exploit-Autor: Ashish Koli (Shikari)
- Hersteller-Homepage: https://thedigitalcraft.com/
- Software-Link: https://github.com/thedigicraft/Atom.CMS
- Version: 2.0
- CVE: CVE-2022-25487
- Über dieses Skript:
- Dieses Skript lädt webshell.php in das Atom CMS hoch. Eine Anwendung speichert diese Datei
- im Uploads-Verzeichnis mit einer eindeutigen Nummer, wodurch wir auf die Webshell zugreifen können.
- Verwendung : python3 exploit.py
- Beispiel: python3 exploit.py 127.0.0.1 80 /atom
- POC: https://youtu.be/qQrq-eEpswc