Skip to content

Download && Delete Anything at /admin/controllers/database.php #16

@R4ilgun

Description

@R4ilgun
                                                        HongCMS

                    0x01 Delete&&download Anything(Admin Privilege)

/admin/controllers/database
image
image

There is a ajax() which can delete or download anything.

The ForceStringFrom() is to receive get or post from user,if we get action is delete and filename is test.txt(default path is /system/backup):

image
image

Delete successfully.
We can delete anthing:
image

image

                                 0x02 Download Anything(Admin Privilege)

image

Just modify the param we get.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions