HongCMS icon indicating copy to clipboard operation
HongCMS copied to clipboard

HongCMS 3.0 - Arbitrary Files Read and Edit in template/edit (Administrator Privilege)

Open Anx1a opened this issue 6 years ago • 0 comments

1.Login to the backstage as the administrator;

2.You need to access the page"http://10.12.11.184/hongcms-master/admin/index.php/template" image

3.Change the file name you want to edit or read in the URL and access this page. For example: "http://10.12.11.184/hongcms-master/admin/index.php/template/edit?dir=../../&file=index.php". image

4.You can see that index.php has been read and edited.

Anx1a avatar Nov 28 '19 08:11 Anx1a