bg5sbk / MiniCMS

至简的个人网站内容管理系统
http://1234n.com/?projects/minicms/
227 stars 61 forks source link

file inclusion vulnerability #36

Closed cilan2 closed 3 years ago

cilan2 commented 5 years ago

Require: PHP Version <5.3.4 magic_quotes_gpc=off 1. require $index_file $index_file = '../mc-files/posts/index/'.$post_old_state.'.php' $post_old_state = $data['state'] image 2. write a page or article with content image 3. can see url is image so filename is 2kbz44.bat 4.use burppsuite,we can find phpinfo in response

微信图片_20190823152524