CYBER RAVENS TEAM

// SECURITY ASSESSMENT - PENTEST COMPLETE //

root@cyberravens:~$ ./scan --target lsh-hotel.com --full
[+] Target resolved: lsh-hotel.com
[+] Web server: Apache/2.x
[+] CMS/Editor: KindEditor 4.1.x
[!] VULNERABILITY: File Upload Bypass (CVE-2017-1002024)
[!] VULNERABILITY: Stored XSS (CVE-2021-42227)
[+] Shell uploaded: /kindeditor/attached/file/cyberravens.html
root@cyberravens:~$ cat flag.txt
Access Granted // No Authentication Required
root@cyberravens:~$
Target
lsh-hotel.com
Vulnerability
File Upload
Access
Granted

Bu sistem KindEditor 4.1.x versiyasını işlədir və

file upload zəifliyi (CVE-2017-1002024) aşkar edilmişdir.

Heç bir autentifikasiya tələb olunmadan .html/.txt faylları

yüklənə bilər. Bu fayl bunun sübutudur.

· ───── · ───── · ───── · ───── ·

Cyber Ravens Team · Security Assessment · PoC