Skip to content

shiro版本过低导致漏洞 #48

@n0-traces

Description

@n0-traces

此版本是shiro 1.2.3 存在shiro反序列漏洞,自己玩可以,别放在公网上面
验证方式:使用shiro反序列工具直接可以爆破rememberMe,然后就可以打
验证链接博客:https://www.cnblogs.com/Mikasa02/p/18084963

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions