Content Management (CMS)

Common

Basics

October CMS

  • Open source self-hosted CMS platform

  • Based on the Laravel PHP

  • Look for unauthenticated exploits:

    • searchsploit october

    • Found: Vulnerable Upload php5 (authenticated)

  • Google: "Vanilla forum download"

  • Admin Panel:

    • Google "october cms admin login"

    • dirb http://10.x.x.x

    • http://10.x.x.x/backend

    • Try guessing: admin/admin

  • Upload php5

    • October > Admin > Media > Upload > oct.php5

    • Execute has a button

    • Catch with nc reverse shell or msfconsole

Last updated