Sign inSign up

vulfocus/tomcat-cve_2020_9484

By vulfocus

•Updated over 6 years ago

CVE-2020-9484 tomcat session持久化漏洞

Image
1

6.6K

vulfocus/tomcat-cve_2020_9484 repository overview

当使用tomcat时,如果使用了tomcat提供的session持久化功能,如果存在文件上传功能,恶意请求者通过一个流程,将能发起一个恶意请求造成服务端远程命令执行。

通过 POST 方式通过 /upload 进行上传文件,参数名称为 file:

Tag summary

Content type

Image

Digest

Size

264.3 MB

Last updated

over 6 years ago

docker pull vulfocus/tomcat-cve_2020_9484