RiteCMS 2.2.1 - Authenticated Remote Code
Januari 13, 2021
6
# Exploit Title: RiteCMS 2.2.1 - Authenticated Remote Code Execution
# Date: 2020-07-03
# Exploit Author: Enes Özeser
# Vendor Homepage: http://ritecms.com/
# Version: 2.2.1
# Tested on: LinuxDork:intext:"Powered By RiteCMS"1- Go to following url. >> http://(HOST)/cms/
2- Default username and password is admin:admin. We must know login credentials.
3- Go "Filemanager" and press "Upload file" button.
4- Choose your php webshell script and upload it.shell access?http://target.com/media/yourshell.phpRef? RiteCMS 2.2.1