前置基础 相关漏洞 CVE-2021-33037 HTTP Request Smuggling https://xz.aliyun.com/t/9866 CVE-2020-9484 Session Deserialization -> RCE https://mp.weixin.qq.com/s/r8Mk1TYJqFIxDk8SkWorrg CVE-2020-13935 WebSocket DoS https://xz.aliyun.com/t/8550 CVE-2020-1938 AJP File Read/Inclusion -> RCE https://www.anquanke.com/post/id/199448 https://xz.aliyun.com/t/7325 CVE-2019-0232 CGI Servlet RCE https://paper.seebug.org/958/ CVE-2019-0221 XSS https://www.exploit-db.com/exploits/50119 CVE-2018-11784 Open Redirect https://www.exploit-db.com/exploits/50118 CVE-2017-12617 HTTP PUT -> RCE(12615 bypass) https://www.exploit-db.com/exploits/43008 CVE-2017-12615 HTTP PUT -> RCE https://xz.aliyun.com/t/5610 利用研究 URL解析差异 回显 内存马 中间件持久化后门 https://gv7.me/articles/2021/an-idea-of-keeping-persistent-backdoor-in-tomcat-middleware/ https://xz.aliyun.com/t/10582 https://xz.aliyun.com/t/10577