Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2024-54879 — CVE-2024-54879 | Kitploit
工具/GitHubGitHub/ailenye/cve-2024-54879
漏洞分析Web应用程序漏洞利用渗透测试错误配置学习与教育
GitHubailenye/cve-2024-54879

CVE-2024-54879

CVE-2024-54879

查看仓库
21年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

一、Project overview

itemcontentremark
Authorized penetration rangehttp://192.168.88.141/Local test
Source code downloadhttps://www.seacms.net/SeaCMS_V13.1_install_f.zipOpen source project
Scope of vulnerabilitySeaCMS_V13.1

二、Vulnerability description

1、Logic bug - Unlimited top-up members

categorycontent

*Visit a center and click on Super Member*

img

*Click on 100 gold per month and grab the pack*

image-20241228233046755

*If the gid parameter is changed to 1, the system returns that the recharge is successful*

image-20241228233155449

*Refresh the Personal Center page, successfully add one month membership time*

image-20241228233211064

*Multiple packages, refresh the personal center page again, you can see the time lengthened*

image-20241228233238238

下载工具
remark
Vulnerability location(URL)http://192.168.200.141/member.php?action=hyz&gid=3&mon=1
Vulnerability typeLogic hole
Vulnerability descriptionSeaCMS has a logical flaw that could be exploited by an attacker to allow any user to recharge members indefinitely