8000 [Bug] Codeinject的host部分由于pom.xml更新了tomcat 版本导致打不通 · Issue #78 · JoyChou93/java-sec-code · GitHub
[go: up one dir, main page]

Skip to content
[Bug] Codeinject的host部分由于pom.xml更新了tomcat 版本导致打不通 #78
Closed
@ek1ng

Description

@ek1ng

对于接口/codeinject/host,预期是通过修改host命令注入。

pom.xml中由于此Commit https://github.com/JoyChou93/java-sec-code/commit/621c30050f82379afe1e2e6d4ff66c1234f33913,本地启动项目的话tomcat是8.5.85 的版本。这个版本的tomcat会对host的格式做检验,对于例如host: localhost;cat /flaghost值,会认为; /这些字符不符合,从而导致打不通。

8.5.85
image
image
image

tomcat是8.5.11的话,可以正常打通。
image
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0