Dudubao has two Command Execution Vulnerabilities (getshell can be used) in a system)
To prove this, getshell does not download any data and delete any files.
------------------------------------------------------------------
The "dudubao city public transport card online payment platform", developed and operated by jiyitong, is the only online payment platform in China that accesses the bus card of multiple cities, currently, it has been connected to more than 20 cities, including Shenzhen, Xiamen, Chongqing, Qingdao, Harbin, Ningbo, and Nanchang. It is estimated that duobao will be connected to 50 cities in 2015, it provides more convenient, safe, and efficient value-added services for 0.3 billion city bus card users nationwide.
Http://enquiry.dodopal.com: 9997/fapaym/login. action Vulnerability No.: S-016 Vulnerability No.: S-005
Old vulnerabilities are not patched yet ····
Solution:
Patch