Skip to content

SecGus/grav-mal-zip

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

Malicious Zip to achieve RCE on Grav CMS if authenticated.

Tested on Grav CMS v1.6.24 - Admin v1.9.14

Usage:

  1. Download ZIP
  2. Log in to the CMS
  3. Go to themes
  4. Upload new theme
  5. Add "cmd" get parameter for command execution.

http://localhost/grav/grav-admin/admin/themes?cmd=whoami

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published