Quanyou home Terminal Management System Remote Command Execution
Logon address
Http://tcm.iquanyou.com.cn/tcm/userLogin.action
Vulnerability exists, but the system will jump automatically
Http://tcm.iquanyou.com.cn/tcm/frameLogin.jsp
So upload a file named frameLogin. jsp.
Upload a sentence
Complete configuration information
# Jdbc. connection. infojdbc. driver = oracle. jdbc. driver. OracleDrivermysql. jdbc. url = jdbc: mysql: // 192.168.14.132: 3306/crm? CharacterEncoding = UTF-8 & zeroDateTimeBehavior = convertToNulljdbc. url = jdbc: oracle: thin: @ 10.10.0.156: 1521: tcm # jdbc. url = jdbc: oracle: thin: @ 10.10.0.57: 1521: tcmjdbc. username = tcm # jdbc. password = tcmjdbc. password = mip2tcmmysql. jdbc. driver = com. mysql. jdbc. driver # mysql. jdbc. url = jdbc: mysql: // localhost: 3306/mixcall? CharacterEncoding = UTF-8 & zeroDateTimeBehavior = convertToNull & transformedBitIsBoolean = truemysql. jdbc. username = rootmysql. jdbc. password = psxuser. name = adminuser. password = admin # sap. username = ZTCM001 # sap. password = 123456sap. username = ZITCM001sap. password = tcmlzy123bpm. username = bpmbpm. password = bpm # ZITCM001 \ u5bc6 \ u7801tcmlzy123user. name = adminuser. password = adminsap. username = ZITCM001sap. password = tcmtcm # sap. username = ZITCM001 # sap. password = tcmlzy123crm. username = crmtcm011crm. password = tcmcrm110bpm. username = bpmbpm. password = bpm # the webservice username and password gw provided by tcm to the official website. userName = tcmguusergw. passWord = tcmgwpass # the webservice information GWurl provided to Tcm on the official website = http://user.quanyou.com.cn/CardServer.wsdltcm.username = Qyhyusernametcm. password = qyhypassword
Solution:
ST framework complementing