环境

image-20230209095051994

image-20230210091106500

  • 先扫一下后台

image-20230210091930392

image-20230210092000021

image-20230210092033838

http://192.168.169.233:26889/index.php?m=Admin&c=index&a=login

根据靶场提示 账号密码都是 adminadmin

image-20230210092240998

漏洞点

image-20230210095338278

image-20230210095708805

image-20230210095807250