English 中文(简体)
[w-2160里亚尔] 页: 1
原标题:[ww-2160 struts] Is <s:property value=%{ xyz }>

This is regarding the security flaw in OGNL evaluation is struts.
Can someone give an example how this is exploited?

Imagine I have a request parameter and server returns this back to the client:
http://test/xyz=test

我有一个名为xyz的变数,在行动类别和共同方案中,可登录和编造。 我有:

<s:property value="%{xyz}" />

如果有人使用URL http://test/xyz=@System@exit(0) 发生什么?

最佳回答
问题回答

暂无回答




相关问题
Recommended way to develop using Jetty and Eclipse

I am currently developing a J2EE application and I would like to use Jetty. I would like to have iot integrated with Eclipse, so I could debug the appliaction. I ve tried out couple of plugins (...

Call function periodically in Java

we need run one function periodically in Java web application . How to call function of some class periodically ? Is there any way that call function when some event occured like high load in server ...

Why make an EJB rather than a Web Service?

I would have thought that there is a lot of information out there on this, but I haven t found anything that really answers my question. What are the advantages of making an EJB rather than a web ...

Where should I put this configuration setting?

I m designing a fairly small web application which will run on a Sun application server (v9.1). It only has a few pages, no database of its own, and will retrieve/update data via web services. There s ...

JNDI Names -- Is Prefix "jdbc/" needed?

What s up with JNDI names? I m trying to get a javax.sql.DataSource using the new annotations feature of Java 5. It s not working for me, so I want to ask... I have a in my web.xml, inside of it is ...

hibernate interceptors : afterTransactionCompletion

I wrote a Hibernate interceptor : public class MyInterceptor extends EmptyInterceptor { private boolean isCanal=false; public boolean onSave(Object entity, Serializable arg1, Object[] arg2, String[]...