Hack UploadFile in DVBBS under v7.0.0 SP2

来源:互联网 发布:汕头政府网络问政平台 编辑:程序博客网 时间:2024/06/05 10:25

There are 2 holes in DvBBS under v7.0.0 SP2, so we may use them to upload arbitrary file to the server.

The holes existed in upfile.asp and saveannouce_upload.asp, the two files were used to upload faces and files to server.

We must construct a customized HTTP POST package to cheat the server. There are many tools in the internet to help us hack it.

原创粉丝点击