Skip to content

Commit

Permalink
'更新金山V8多个漏洞:tada:'
Browse files Browse the repository at this point in the history
  • Loading branch information
PeiQi0 committed Apr 24, 2021
1 parent d51991b commit cd93b22
Show file tree
Hide file tree
Showing 337 changed files with 7,285 additions and 1,876 deletions.
File renamed without changes.
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
## 漏洞复现

存在漏洞的文件 **/htmltopdf/downfile.php**
存在漏洞的文件 **/Console/htmltopdf/downfile.php**

```php
<?php
Expand Down
6 changes: 3 additions & 3 deletions _book/Goby & POC.html
Original file line number Diff line number Diff line change
Expand Up @@ -1612,9 +1612,9 @@

</li>

<li class="chapter " data-level="2.3.3" data-path="PeiQi_Wiki/Web应用漏洞/Hue/README.md">
<li class="chapter " data-level="2.3.3" data-path="PeiQi_Wiki/Web应用漏洞/Hue/">

<span>
<a href="PeiQi_Wiki/Web应用漏洞/Hue/">


Hue
Expand Down Expand Up @@ -5372,7 +5372,7 @@ <h1 class="search-results-title">No results matching "<span class='search-query'
<script>
var gitbook = gitbook || [];
gitbook.push(function() {
gitbook.page.hasChanged({"page":{"title":"Goby & POC","level":"1.2","depth":1,"next":{"title":"更新时间线记录","level":"1.3","depth":1,"path":"TIME.md","ref":"TIME.md","articles":[]},"previous":{"title":"关于文库","level":"1.1","depth":1,"path":"README.md","ref":"README.md","articles":[]},"dir":"ltr"},"config":{"plugins":["back-to-top-button","expandable-chapters","theme-comscore","splitter","alerts","chapter-fold","code","github","favicon","accordion","-lunr","-search","search-pro","emphasize","-sharing","sharing-plus","tbfed-pagefooter","lightbox","flexible-alerts","pageview-count","livereload"],"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"pluginsConfig":{"tbfed-pagefooter":{"copyright":"PeiQi WiKi文库","modify_label":"文件更新时间:","modify_format":"YYYY-MM-DD HH:mm:ss"},"chapter-fold":{},"emphasize":{},"github":{"url":"https://github.com/PeiQi0/PeiQi-WIKI"},"livereload":{},"splitter":{},"search-pro":{},"accordion":{},"sharing-plus":{"qq":false,"all":["facebook","google","twitter","instapaper","linkedin","pocket","stumbleupon"],"douban":false,"facebook":true,"weibo":false,"instapaper":false,"whatsapp":false,"hatenaBookmark":false,"twitter":true,"messenger":false,"line":false,"vk":false,"pocket":true,"google":false,"viber":false,"stumbleupon":false,"qzone":false,"linkedin":false},"code":{"copyButtons":true},"fontsettings":{"theme":"white","family":"sans","size":2},"highlight":{},"favicon":{},"lightbox":{"jquery":true,"sameUuid":false},"theme-comscore":{},"back-to-top-button":{},"pageview-count":{},"alerts":{},"flexible-alerts":{"danger":{"className":"danger","icon":"fa fa-ban","label":"Attention"},"note":{"className":"info","icon":"fa fa-info-circle","label":"Note"},"style":"callout","tip":{"className":"tip","icon":"fa fa-lightbulb-o","label":"Tip"},"warning":{"className":"warning","icon":"fa fa-exclamation-triangle","label":"Warning"}},"sharing":{},"theme-default":{"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"showLevel":false},"expandable-chapters":{}},"theme":"default","author":"PeiQi","pdf":{"pageNumbers":true,"fontSize":12,"fontFamily":"Arial","paperSize":"a4","chapterMark":"pagebreak","pageBreaksBefore":"/","margin":{"right":62,"left":62,"top":56,"bottom":56}},"structure":{"langs":"LANGS.md","readme":"README.md","glossary":"GLOSSARY.md","summary":"SUMMARY.md"},"variables":{},"title":"PeiQi WiKi文库","language":"zh-hans","gitbook":"*","description":"WiKi文库"},"file":{"path":"Goby & POC.md","mtime":"2021-04-14T12:55:36.453Z","type":"markdown"},"gitbook":{"version":"3.2.3","time":"2021-04-22T11:31:37.292Z"},"basePath":".","book":{"language":""}});
gitbook.page.hasChanged({"page":{"title":"Goby & POC","level":"1.2","depth":1,"next":{"title":"更新时间线记录","level":"1.3","depth":1,"path":"TIME.md","ref":"TIME.md","articles":[]},"previous":{"title":"关于文库","level":"1.1","depth":1,"path":"README.md","ref":"README.md","articles":[]},"dir":"ltr"},"config":{"plugins":["back-to-top-button","expandable-chapters","theme-comscore","splitter","alerts","chapter-fold","code","github","favicon","accordion","-lunr","-search","search-pro","emphasize","-sharing","sharing-plus","tbfed-pagefooter","lightbox","flexible-alerts","pageview-count","livereload"],"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"pluginsConfig":{"tbfed-pagefooter":{"copyright":"PeiQi WiKi文库","modify_label":"文件更新时间:","modify_format":"YYYY-MM-DD HH:mm:ss"},"chapter-fold":{},"emphasize":{},"github":{"url":"https://github.com/PeiQi0/PeiQi-WIKI"},"livereload":{},"splitter":{},"search-pro":{},"accordion":{},"sharing-plus":{"qq":false,"all":["facebook","google","twitter","instapaper","linkedin","pocket","stumbleupon"],"douban":false,"facebook":true,"weibo":false,"instapaper":false,"whatsapp":false,"hatenaBookmark":false,"twitter":true,"messenger":false,"line":false,"vk":false,"pocket":true,"google":false,"viber":false,"stumbleupon":false,"qzone":false,"linkedin":false},"code":{"copyButtons":true},"fontsettings":{"theme":"white","family":"sans","size":2},"highlight":{},"favicon":{},"lightbox":{"jquery":true,"sameUuid":false},"theme-comscore":{},"back-to-top-button":{},"pageview-count":{},"alerts":{},"flexible-alerts":{"danger":{"className":"danger","icon":"fa fa-ban","label":"Attention"},"note":{"className":"info","icon":"fa fa-info-circle","label":"Note"},"style":"callout","tip":{"className":"tip","icon":"fa fa-lightbulb-o","label":"Tip"},"warning":{"className":"warning","icon":"fa fa-exclamation-triangle","label":"Warning"}},"sharing":{},"theme-default":{"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"showLevel":false},"expandable-chapters":{}},"theme":"default","author":"PeiQi","pdf":{"pageNumbers":true,"fontSize":12,"fontFamily":"Arial","paperSize":"a4","chapterMark":"pagebreak","pageBreaksBefore":"/","margin":{"right":62,"left":62,"top":56,"bottom":56}},"structure":{"langs":"LANGS.md","readme":"README.md","glossary":"GLOSSARY.md","summary":"SUMMARY.md"},"variables":{},"title":"PeiQi WiKi文库","language":"zh-hans","gitbook":"*","description":"WiKi文库"},"file":{"path":"Goby & POC.md","mtime":"2021-04-14T12:55:36.453Z","type":"markdown"},"gitbook":{"version":"3.2.3","time":"2021-04-24T02:58:16.924Z"},"basePath":".","book":{"language":""}});
});
</script>
</div>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1612,9 +1612,9 @@

</li>

<li class="chapter " data-level="2.3.3" data-path="../../Web应用漏洞/Hue/README.md">
<li class="chapter " data-level="2.3.3" data-path="../../Web应用漏洞/Hue/">

<span>
<a href="../../Web应用漏洞/Hue/">


Hue
Expand Down Expand Up @@ -5295,7 +5295,7 @@ <h2 id="fofa">FOFA</h2>
<h2 id="&#x6F0F;&#x6D1E;&#x590D;&#x73B0;">&#x6F0F;&#x6D1E;&#x590D;&#x73B0;</h2>
<p>&#x8BBF;&#x95EE;&#x5982;&#x4E0B;URL&#xFF0C;&#x6CC4;&#x9732;&#x7528;&#x6237;&#x540D;&#x4E0E;&#x767B;&#x5F55;IP</p>
<pre><code>http://xxx.xxx.xxx.xxx/admin/index.php?m=admin&amp;c=log&amp;a=table_json&amp;json=get&amp;soso_ok=1&amp;t=user_login_log&amp;page=1&amp;limit=10&amp;bsphptime=1600407394176&amp;soso_id=1&amp;soso=&amp;DESC=0&#x2018;
</code></pre><p><a href="image/bsphp-1.png" data-lightbox="814f4efb-f736-48e8-838f-c94049439438" data-title=""><img src="image/bsphp-1.png" alt=""></a></p>
</code></pre><p><a href="image/bsphp-1.png" data-lightbox="5a89e791-5a42-494a-8a84-0c78a96e367e" data-title=""><img src="image/bsphp-1.png" alt=""></a></p>
<footer class="page-footer"><span class="copyright">PeiQi WiKi&#x6587;&#x5E93; all right reserved&#xFF0C;powered by Gitbook</span><span class="footer-modification">&#x6587;&#x4EF6;&#x66F4;&#x65B0;&#x65F6;&#x95F4;&#xFF1A;
2021-03-17 21:41:40
</span></footer>
Expand Down Expand Up @@ -5341,7 +5341,7 @@ <h1 class="search-results-title">No results matching "<span class='search-query'
<script>
var gitbook = gitbook || [];
gitbook.push(function() {
gitbook.page.hasChanged({"page":{"title":"BSPHP 未授权访问 信息泄露漏洞","level":"2.7.6.1","depth":3,"next":{"title":"极致CMS","level":"2.7.7","depth":2,"path":"PeiQi_Wiki/CMS漏洞/极致CMS/README.md","ref":"PeiQi_Wiki/CMS漏洞/极致CMS/README.md","articles":[{"title":"极致CMS 任意文件上传(后台权限)","level":"2.7.7.1","depth":3,"path":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS_全版本任意文件上传.md","ref":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS_全版本任意文件上传.md","articles":[]},{"title":"极致CMS 1.71 + 1.7 + 1.67 版本sql注入","level":"2.7.7.2","depth":3,"path":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS_1.71_1.7_1.67版本sql注入.md","ref":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS_1.71_1.7_1.67版本sql注入.md","articles":[]},{"title":"极致CMS <1.81 版本 存储型XSS","level":"2.7.7.3","depth":3,"path":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS 1.81以下版本 存储型XSS.md","ref":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS 1.81以下版本 存储型XSS.md","articles":[]}]},"previous":{"title":"BSPHP","level":"2.7.6","depth":2,"path":"PeiQi_Wiki/CMS漏洞/BSPHP/README.md","ref":"PeiQi_Wiki/CMS漏洞/BSPHP/README.md","articles":[{"title":"BSPHP 未授权访问 信息泄露漏洞","level":"2.7.6.1","depth":3,"path":"PeiQi_Wiki/CMS漏洞/BSPHP/BSPHP 未授权访问 信息泄露漏洞.md","ref":"PeiQi_Wiki/CMS漏洞/BSPHP/BSPHP 未授权访问 信息泄露漏洞.md","articles":[]}]},"dir":"ltr"},"config":{"plugins":["back-to-top-button","expandable-chapters","theme-comscore","splitter","alerts","chapter-fold","code","github","favicon","accordion","-lunr","-search","search-pro","emphasize","-sharing","sharing-plus","tbfed-pagefooter","lightbox","flexible-alerts","pageview-count","livereload"],"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"pluginsConfig":{"tbfed-pagefooter":{"copyright":"PeiQi WiKi文库","modify_label":"文件更新时间:","modify_format":"YYYY-MM-DD HH:mm:ss"},"chapter-fold":{},"emphasize":{},"github":{"url":"https://github.com/PeiQi0/PeiQi-WIKI"},"livereload":{},"splitter":{},"search-pro":{},"accordion":{},"sharing-plus":{"qq":false,"all":["facebook","google","twitter","instapaper","linkedin","pocket","stumbleupon"],"douban":false,"facebook":true,"weibo":false,"instapaper":false,"whatsapp":false,"hatenaBookmark":false,"twitter":true,"messenger":false,"line":false,"vk":false,"pocket":true,"google":false,"viber":false,"stumbleupon":false,"qzone":false,"linkedin":false},"code":{"copyButtons":true},"fontsettings":{"theme":"white","family":"sans","size":2},"highlight":{},"favicon":{},"lightbox":{"jquery":true,"sameUuid":false},"theme-comscore":{},"back-to-top-button":{},"pageview-count":{},"alerts":{},"flexible-alerts":{"danger":{"className":"danger","icon":"fa fa-ban","label":"Attention"},"note":{"className":"info","icon":"fa fa-info-circle","label":"Note"},"style":"callout","tip":{"className":"tip","icon":"fa fa-lightbulb-o","label":"Tip"},"warning":{"className":"warning","icon":"fa fa-exclamation-triangle","label":"Warning"}},"sharing":{},"theme-default":{"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"showLevel":false},"expandable-chapters":{}},"theme":"default","author":"PeiQi","pdf":{"pageNumbers":true,"fontSize":12,"fontFamily":"Arial","paperSize":"a4","chapterMark":"pagebreak","pageBreaksBefore":"/","margin":{"right":62,"left":62,"top":56,"bottom":56}},"structure":{"langs":"LANGS.md","readme":"README.md","glossary":"GLOSSARY.md","summary":"SUMMARY.md"},"variables":{},"title":"PeiQi WiKi文库","language":"zh-hans","gitbook":"*","description":"WiKi文库"},"file":{"path":"PeiQi_Wiki/CMS漏洞/BSPHP/BSPHP 未授权访问 信息泄露漏洞.md","mtime":"2021-03-17T13:41:40.861Z","type":"markdown"},"gitbook":{"version":"3.2.3","time":"2021-04-22T11:31:37.292Z"},"basePath":"../../..","book":{"language":""}});
gitbook.page.hasChanged({"page":{"title":"BSPHP 未授权访问 信息泄露漏洞","level":"2.7.6.1","depth":3,"next":{"title":"极致CMS","level":"2.7.7","depth":2,"path":"PeiQi_Wiki/CMS漏洞/极致CMS/README.md","ref":"PeiQi_Wiki/CMS漏洞/极致CMS/README.md","articles":[{"title":"极致CMS 任意文件上传(后台权限)","level":"2.7.7.1","depth":3,"path":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS_全版本任意文件上传.md","ref":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS_全版本任意文件上传.md","articles":[]},{"title":"极致CMS 1.71 + 1.7 + 1.67 版本sql注入","level":"2.7.7.2","depth":3,"path":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS_1.71_1.7_1.67版本sql注入.md","ref":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS_1.71_1.7_1.67版本sql注入.md","articles":[]},{"title":"极致CMS <1.81 版本 存储型XSS","level":"2.7.7.3","depth":3,"path":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS 1.81以下版本 存储型XSS.md","ref":"PeiQi_Wiki/CMS漏洞/极致CMS/极致CMS 1.81以下版本 存储型XSS.md","articles":[]}]},"previous":{"title":"BSPHP","level":"2.7.6","depth":2,"path":"PeiQi_Wiki/CMS漏洞/BSPHP/README.md","ref":"PeiQi_Wiki/CMS漏洞/BSPHP/README.md","articles":[{"title":"BSPHP 未授权访问 信息泄露漏洞","level":"2.7.6.1","depth":3,"path":"PeiQi_Wiki/CMS漏洞/BSPHP/BSPHP 未授权访问 信息泄露漏洞.md","ref":"PeiQi_Wiki/CMS漏洞/BSPHP/BSPHP 未授权访问 信息泄露漏洞.md","articles":[]}]},"dir":"ltr"},"config":{"plugins":["back-to-top-button","expandable-chapters","theme-comscore","splitter","alerts","chapter-fold","code","github","favicon","accordion","-lunr","-search","search-pro","emphasize","-sharing","sharing-plus","tbfed-pagefooter","lightbox","flexible-alerts","pageview-count","livereload"],"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"pluginsConfig":{"tbfed-pagefooter":{"copyright":"PeiQi WiKi文库","modify_label":"文件更新时间:","modify_format":"YYYY-MM-DD HH:mm:ss"},"chapter-fold":{},"emphasize":{},"github":{"url":"https://github.com/PeiQi0/PeiQi-WIKI"},"livereload":{},"splitter":{},"search-pro":{},"accordion":{},"sharing-plus":{"qq":false,"all":["facebook","google","twitter","instapaper","linkedin","pocket","stumbleupon"],"douban":false,"facebook":true,"weibo":false,"instapaper":false,"whatsapp":false,"hatenaBookmark":false,"twitter":true,"messenger":false,"line":false,"vk":false,"pocket":true,"google":false,"viber":false,"stumbleupon":false,"qzone":false,"linkedin":false},"code":{"copyButtons":true},"fontsettings":{"theme":"white","family":"sans","size":2},"highlight":{},"favicon":{},"lightbox":{"jquery":true,"sameUuid":false},"theme-comscore":{},"back-to-top-button":{},"pageview-count":{},"alerts":{},"flexible-alerts":{"danger":{"className":"danger","icon":"fa fa-ban","label":"Attention"},"note":{"className":"info","icon":"fa fa-info-circle","label":"Note"},"style":"callout","tip":{"className":"tip","icon":"fa fa-lightbulb-o","label":"Tip"},"warning":{"className":"warning","icon":"fa fa-exclamation-triangle","label":"Warning"}},"sharing":{},"theme-default":{"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"showLevel":false},"expandable-chapters":{}},"theme":"default","author":"PeiQi","pdf":{"pageNumbers":true,"fontSize":12,"fontFamily":"Arial","paperSize":"a4","chapterMark":"pagebreak","pageBreaksBefore":"/","margin":{"right":62,"left":62,"top":56,"bottom":56}},"structure":{"langs":"LANGS.md","readme":"README.md","glossary":"GLOSSARY.md","summary":"SUMMARY.md"},"variables":{},"title":"PeiQi WiKi文库","language":"zh-hans","gitbook":"*","description":"WiKi文库"},"file":{"path":"PeiQi_Wiki/CMS漏洞/BSPHP/BSPHP 未授权访问 信息泄露漏洞.md","mtime":"2021-03-17T13:41:40.861Z","type":"markdown"},"gitbook":{"version":"3.2.3","time":"2021-04-24T02:58:16.924Z"},"basePath":"../../..","book":{"language":""}});
});
</script>
</div>
Expand Down
Loading

0 comments on commit cd93b22

Please sign in to comment.