
Codiad 2.8.4及更早版本允许远程代码执行,这是与CVE-2017-11366和CVE-2017-15689不同的漏洞。
@ git clone https://github.com/Codiad/Codiad.git
复现步骤 1. 在 ubuntu 服务器上使用 Codiad 2.8.4(最新版本)搭建一个易受攻击的环境
@ chmod o+w config.php
@ chmod o+w workspace
@ chmod o+w plugins
@ chmod o+w themes
@ chmod o+w data
2.
@ git clone https://github.com/hidog123/Codiad-CVE-2018-14009.gi
3. 运行漏洞利用脚本,然后获得一个反弹 shell