文件包含漏洞整理 (7)

EXP:

http://www.ctfs-wiki.com/FI/FI.php ?filename=test.txt........................................................................................................................................................................
..........................................................................................................................................................................................
..........................................................................................................................................................................................
..........................................................................................................................................................................................
..........................................................................................................................................................................................
..........................................................................................................................................................................................
.......................................................................................................................

测试结果

3.有限制远程文件包含漏洞绕过

测试代码:

<?php include($_GET[\'filename\'] . ".html"); ?>

代码中多添加了html后缀,导致远程包含的文件也会多一个html后缀。

内容版权声明:除非注明,否则皆为本站原创文章。

转载注明出处:https://www.heiqu.com/zwpdpf.html