You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Code Audit:
Src/main/java/com/mysiteform/admin/service/ipl/LocalUploadServiceImpl. The upload file in src/main/java is not protected, resulting in the ability to upload JSP Trojans and HTML files
Vulnerability exploitation:
Upload image interface, just did front-end suffix verification. First upload the image file, then capture the package and change the suffix to JSP or HTML
Code Audit:


Src/main/java/com/mysiteform/admin/service/ipl/LocalUploadServiceImpl. The upload file in src/main/java is not protected, resulting in the ability to upload JSP Trojans and HTML files
Vulnerability exploitation:

Upload image interface, just did front-end suffix verification. First upload the image file, then capture the package and change the suffix to JSP or HTML
http://192.168.52.132:8080/static/upload/db499a9f-c726-409d-b741-2cb82e1a9b01.jsp
http://192.168.52.132:8080/static/upload/f4c37e5f-b649-4a06-9075-11aa7d4a885a.html
The text was updated successfully, but these errors were encountered: