level2-ezForgery
我不告诉你
反弹shell
CEYE - Monitor service for security testing
<?php
error_reporting(0);
highlight_file(__FILE__);
$cmd=$_GET['cmd'];
if(!preg_match("/flag|dns1og|request|txt|1s|php|pass|echo|</i",$cmd)){
shell_exec($cmd);
}else{
echo "这这不对吧?";
}
/*有的人真的很粗心*/
?>
simplephp
PHP/8.1.0-dev漏洞