Apache SSI remote command execution vulnerability
Vulnerability principle:
When testing for arbitrary file upload vulnerabilities, the target server may not be allowed to upload files with the php suffix. If the target server has SSI and CGI support enabled, we can upload a shtml file and execute arbitrary commands using syntax.
Recurrence of vulnerabilities:
The shtml contains the text that the embedded server contains commands, and the server fully reads, analyzes, and modifies the SHTML document before it is sent to the browser.
Normal upload of PHP files is not allowed. We can upload a shell.shtml file:
And then upload it.
Click in
Parsing is successful, remote commands are executed, and pwd commands can be changed at will.