#
 
Nmap Output
 
 
 
Home Page:
 
 
/fuel Page
 
 
I logged in to CMS as admin with information at fuelcms home page but nothing useful. Lets scan for any exploit for fuel cms 1.4
 
 
I found a code that would work for me and copied it to the desktop.
 
 
It doesn't work with python3. It seemed to work when I ran it with Python2.
 
 
But doesnt work.
 
 
I found the edited version.
 
 
Now it works. but not enough
 
I shared phpbash from the host and opened it on the website.
 
 
 
At this stage, neither sudo -l is running nor anything else. We entered as a user and got the user.txt.
 
I've tried several attempts to upgrade, but in vain.
 
Importance of searching information about the site:
 
 
The file contains root and password.
 
 
I had a hard time at this stage. I couldn't run commands like su or sudo even though I knew the root password. With help from the internet, I was able to run the su command with the following method.