Joro 是一个网络利用(web exploitation)框架。在 1.1.1 版本之前,Joro 的默认代理模式会在 127.0.0.1:9090 上暴露一个本地 API,该 API 不进行身份验证,并应用了通配符 CORS 策略。由于插件上传使用的是在 CORS 中被列为安全类型的 multipart/form-data 内容类型,因此,运营者访问的任何页面上的跨域 JavaScript 都可以直接通过运营者的浏览器访问特权限定的端点——包括上传原生插件并触发重启——且无需预检请求(preflight)或凭据
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet