PHP audit learning experiment Series metinfo5.3 understand

This vulnerability is variable coverage holes contained in the file, you can see, module originally is empty, not when fmodule 7, they begin to do some assignment, including the module.

And the value of fmodule can also be passed here on concern a code common.inc.php file.

 

We look at the output of the output value is passed, you can see fmodule can be covered, and the value of the module or show.php, has not been passed, the normal logic.

 

 https://blog.csdn.net/Kevinhanser/article/details/81176757

Guess you like

Origin www.cnblogs.com/foe0/p/12018188.html