mirror of
https://github.com/Threekiii/Awesome-POC.git
synced 2025-11-07 11:58:05 +00:00
11 lines
304 B
Markdown
11 lines
304 B
Markdown
|
|
# OneBlog 开源博客管理系统 远程命令执行漏洞
|
|||
|
|
|
|||
|
|
## 漏洞描述
|
|||
|
|
|
|||
|
|
由于使用含有漏洞版本的Apache Shiro和默认的密钥,导致OneBlog存在远程命令执行漏洞。
|
|||
|
|
|
|||
|
|
## 漏洞复现
|
|||
|
|
|
|||
|
|
shiro 默认密钥:
|
|||
|
|
|
|||
|
|

|