Skip to content
This repository has been archived by the owner on Jul 25, 2024. It is now read-only.

NettyMemshell 注入成功时漏洞缺报 #36

Open
c0r1 opened this issue Oct 15, 2022 · 0 comments
Open

NettyMemshell 注入成功时漏洞缺报 #36

c0r1 opened this issue Oct 15, 2022 · 0 comments

Comments

@c0r1
Copy link

c0r1 commented Oct 15, 2022

漏洞利用状态检查使用的方法错误,这里的 header 实际添加到了 Request Body 中,导致 NettyMemshell 注入成功时检测利用状态失败,导致漏洞缺报

String re6 = HTTPUtils.postRequestV1(target, "?cmd=echo "+ endpoint, header).toString();

image

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant