References https://github.com/k8gege/iisput https://github.com/chaitin/xray/blob/master/pocs/iis-put-getshell.yml https://www.ddpoc.com/DVB-2022-3919.html https://blog.csdn.net/weixin_46062722/article/details/114086240 http://k8gege.org/Ladon/iisput https://www.cnblogs.com/mY-bL0g/p/12818195.html http://k8gege.org/p/iisput.html https://cloud.tencent.cn/developer/article/2148790
Related VulnerabilitiesPoCCVE-2017-7269: Windows Server 2003 & IIS 6.0 - Remote Code ExecutionPoCtongda-insert-sql-inject-getshell: 通达OA v11.6 insert SQL注入漏洞PoCwanhu-oa-attachmentserver-upload-file: 万户 OA 前台无条件 GETSHELLPoCwanhu-oa-officeserverservlet-upload-file: 万户 OA 前台无条件 GETSHELLPoCiis-directory-browsing: IIS Directory Browsing DetectionPoCiis-logging-disabled: IIS Logging Disabled全程云OA存在前台getshell漏洞IIS4 Exair示例站点拒绝服务攻击漏洞学分制系统存在SQL注入漏洞导致GetshellMicrosoft IIS 5.0 CVE-2000-0778 源代码泄露漏洞Microsoft IIS Cachuri TREE_HASH_TABLE 拒绝服务漏洞IIS-PUT-GETSHELL任意文件上传致远OA 前台getshell