4.1K Star 23.1K Fork 6.9K

GVP铭飞 / MCMS

 / 详情

Unauthorized upload vulnerability

已完成
创建于  
2018-10-29 21:57

Since this upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First upload a picture horse, then intercept the data packet in the name parameter that changes the suffix name to jsp, after the release request, the server returns the storage path of the webshell.

评论 (2)

Devote 创建了任务
Devote 修改了描述
Devote 修改了描述
展开全部操作日志

resolved

铭飞 任务状态待办的 修改为已拒绝
铭飞 任务状态已拒绝 修改为已完成

Could anyone provide the fix commit, please?
Thanks

登录 后才可以发表评论

状态
负责人
里程碑
Pull Requests
关联的 Pull Requests 被合并后可能会关闭此 issue
分支
开始日期   -   截止日期
-
置顶选项
优先级
参与者(3)
542665 mingsoft 1578927126
Java
1
https://gitee.com/mingSoft/MCMS.git
git@gitee.com:mingSoft/MCMS.git
mingSoft
MCMS
MCMS

搜索帮助