DNN
Default Creds
RCE
SQL Console
System command can be run via the built-in SQL console under the Settings menu.
After pressing Run Script
OS commands can be executed.
ASP Webshell
If the SuperUser
account is compromised, we can access the Security settings (Figure 1) and allow any file extensions needed so we can upload a webshell (Figure 2).
Get the file's URL by right-clicking and interact with the webshell.
Resources
Last updated
Was this helpful?