PluXml

Exploiting PluXml

CVE-2020-18185

Log into admin panel [URL]/core/admin

Navigate to static page, modify a page and add PHP rev shell code

Start a listener on the the attacker machine

Save the page modifications and view the modifed page to get a shell

Last updated