NodeJS远程代码执行
2017-02-06
18
背景@Artsploit在挖PayPal的漏洞时,发现一处NodeJS代码执行,奖励$10000美金。测试var express = require("express"); var app = express(); app.get("/", function (req, res) { res.send("Hello eval(req.query.q));console.log(req.query.q);});app.listen(8080, functio...