New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add module for ZDI-14-372 Visual Mining NetCharts Remote Code Execution #4139
Merged
kernelsmith
merged 6 commits into
rapid7:master
from
jvazquez-r7:zdi_14_372_visual_mining
Nov 7, 2014
Merged
Add module for ZDI-14-372 Visual Mining NetCharts Remote Code Execution #4139
kernelsmith
merged 6 commits into
rapid7:master
from
jvazquez-r7:zdi_14_372_visual_mining
Nov 7, 2014
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
When header is empty it shouldn't add an starting empty new line
Because the JASPER engine with Tomcat has been found complaining about the out variable.
Juan, I don't think it matters since we're uploading jsp, but did you test on 32bit or 64? |
@kernelsmith, good question, tried on 32 bits system |
Win Server 2008 x64:
|
ooom, thanks @kernelsmith ! :) |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This pull request includes:
#to_s
was adding a bad first new line when the message hadn't headers. Specs have been updated too.out
variable was creating a conflict when JASPER was trying to compile the JSP. I've randomized some 'common' variable names.Verification