The Tongyuan website creation system has the Upload Vulnerability. You can directly upload any file without filtering. All websites of the Tongyuan website creation system have access to www.xxx.com/cms/editor/filemanager/browser/default/browser.html? Type = & Connector = connectors/jsp/connectorType can be used .. /... To upload a jsp file to the cms file at the upper level in the root directory of the website, you can upload the jsp file without filtering, such as www.2cto. comhttp: // www.gpowersoft.com/cms/editor/filemanager/browser/default/browser.html? Type =.../Tomcat5.5 _ Gpower/webapps/cms & Connector = connectors/jsp/connector to upload Jsp files. I don't know why images cannot be uploaded... This is my test http://www.gpowersoft.com/index.txt on the official websiteSolution:You should modify the editor storage path, delete the upload point, or add Filtering for the upload.