Explain the vulnerability of Lanke CMS in detail and take the full tutorial in batch

Keywords: inurl: recruitment/mail_job.asp

Vulnerability page: admin/left.asp

Use keywords to search for a lot of results.

 Lanke CMS vulnerability access webhall

After entering a website at random, add admin/left.asp to the back of the website and directly enter the background.

 twenty-six million one hundred and thirty thousand five hundred and fifteen

Now we start to add management users. First, set the security of the browser

Click Tools → Internet Options, as shown in the figure below:

 one billion twenty-six million one hundred and thirty thousand eight hundred and twenty-four

Then click Security to set the security level of the area to the highest. Click OK, as shown in the following figure:

 twenty-six million one hundred and thirty thousand nine hundred and thirty-one

Then click User Management in Website Management to add a user. The following is what I just added.

 one hundred and thirty-one billion twenty-six million one hundred and thirty-one thousand seven hundred and twenty-five

After adding, set the security zone level of the browser back to default. After refreshing the page, you will come out of the background login place of the website, and then use the user you just added to log in, and then you will start to take the shell. It is very simple to take the shell and directly use data backup.

Find a place to upload at random, upload our sentence in the form of a picture, copy and paste the address obtained after uploading to the current database path, write the name of the backup database and click Backup.

 one hundred and thirty-one billion twenty-six million one hundred and thirty-two thousand five hundred and four

After the backup is successful, copy the address of the horse and start the kitchen knife

 twenty trillion and one hundred and thirty-one billion twenty-six million one hundred and thirty-two thousand eight hundred and fifty-six

 one hundred and thirty-one billion twenty-six million one hundred and thirty-three thousand two hundred and twenty-three

 

 

Original article reprint please specify: reprint from Seven Travelers Blog

Fixed link of this article: https://www.qxzxp.com/3765.html

Explain the vulnerability of Lanke CMS in detail. Take a full tutorial in batch: there are 2 messages at present

  1. 0F
    ujbui :

    In a word, what is a Trojan horse

    2018-10-19 13:04 [Reply]
  2. [Again: Please don't buy pirated website systems on Taobao. We will not provide technical support for pirated websites!] [Recently, many websites that have bought pirated websites have been hacked. Please take this as a lesson and don't be fooled!]

    2014-11-10 10:54 [Reply]

Comment

3 + 9 =

Shortcut key: Ctrl+Enter