lufeirider / CVE-2019-2725

CVE-2019-2725 命令回显

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Content-Length: 0

wubantudl opened this issue · comments

commented

您好,打扰了。
POST /wls-wsat/CoordinatorPortType HTTP/1.1
Host: 127.0.0.1:7001
Accept-Encoding: gzip, deflate
Accept: /
content-type: text/xml
lfcmd: echo lufei test
Content-Length: 264253

response:
HTTP/1.1 200 OK
Date: Sun, 16 Jun 2019 09:07:16 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Length: 0

weblogic-2019-2725_10.3.6回显检测是成功的,代码执行与预期不一致,麻烦您有空时解答一下,十分感谢

weblogic-2019-2725_10.3.6回显检测.txt 能回显?
weblogic-2019-2725_10.3.6命令执行.txt 不能执行?你执行了什么?

commented

没有复现环境,只能猜测是有防护,检测weblogic开启新的进程,被防护拦截了。

commented