-
Notifications
You must be signed in to change notification settings - Fork 2.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add finereport-sqli-file-upload.yaml #10369
Add finereport-sqli-file-upload.yaml #10369
Conversation
Hi @adeljck Is it possible share some reference link to this POC ? Thanks |
add a link about this vuln |
Hi @adeljck This looks like a authenticated template, by seeing the cookie headers in the request can you update the template accordingly Join our discord server and send a DM (#geekfreak) my username Thanks |
Hi @adeljck
With the second request the file will be accessible ? will there be any content to match in the second response body , it will help full if you can share the debug data Thanks |
Hi @adeljck i have found a valid non-intrusive endpoint, where we can confirm the rce vulnerability Let me know if this changes works Thanks |
The jsp file names are randomized and the files are written in a static resource directory. A normally running site will not store jsp files inside this directory |
Hi @adeljck Mostly we try to find a non-intrusive way of template Does the above changes works at your end ? Hello @adeljck , thank you so much for sharing this template with the community and contributing to this project 🍻 You can grab some cool PD stickers over here http://nux.gg/stickers 😄 |
I'll make some changes. Wait a minute. |
Hi @adeljck , hope it's not file upload again 👀 |
Fix it to non-intrusive way |
Hi @adeljck the SSTI payload was easy to understand to the user which i added earlier i'm marking this on hold for my Team Members to Review Further cc @princechaddha Thanks for sharing the details |
it's still on hold,is there still have any question with this file? |
Hi @adeljck we are sticking with the non intrusive payload the SSTI method i'm reverting back the changes Let me know if you have any queries |
Template / PR Information
FineReport-sqli-file-upload
Template Validation
I've validated this template locally?
Additional Details (leave it blank if not applicable)
fofa-query: app="帆软-FineReport"
Additional References: