Skip to content

Geek-framework can upload JSP backdoor #32

@yundiao

Description

@yundiao

I. Source code analysis
/src/main/java/com/geekcattle/controller/console/UeditorController.java
File upload. When an exception of file extension is detected, no exit or return.
CodeAnalysis-en

II. Vulnerability testing
ueditor
Ueditor editor, upload pictures.
The front end validates the file extension, so you need to upload a normal image file.
After using BurpSuite to intercept, modify the upload file name and content.
burpsuite
Geek-framework is a java development framework; the ueditor plug-in here is incomplete, but the back door is uploaded.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions