Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

练了一下vulhub spring的CVE-2022-2965,写了个的poc,headers里的“suffix”、“c1”、“c2”,最终没有写入jsp文件中。 #1690

Open
Abs1n7he opened this issue Dec 2, 2022 · 3 comments

Comments

@Abs1n7he
Copy link

Abs1n7he commented Dec 2, 2022

xray发的包,headers里的“suffix”、“c1”、“c2”,最终没有写入jsp文件中;
xray发的包用burpsuit发,headers里的“suffix”、“c1”、“c2”,成功写入jsp文件中。
image

@Jarcis-cy
Copy link
Collaborator

看起来格式有点问题,可能加载上就报错了,可以提供一下报错信息,运行时,在webscan前面加上--log-level debug查看详细信息,同时建议poc采用我们的规则实验室进行编写

@Abs1n7he
Copy link
Author

Abs1n7he commented Dec 5, 2022

image
写的jsp文件内容成功与失败如图:
image

@mashiro01
Copy link
Collaborator

请问能否提供所示poc的全部内容这里进行验证?这里本地搭建靶场使用xray测试可正常替换内容并写入到文件中

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants