File upload vulnerability upload-libs pass2

File upload vulnerability upload-libs pass2

First View source
Here Insert Picture Description
found to be the back-end PHP filter, allowing only type image / jpeg image / png image / gif file upload, the word Trojan suffix to jpg
Here Insert Picture Description
upload pictures and capture

Here Insert Picture Description
Send to Repeater
Here Insert Picture Description
modify the file suffix .php
Go
Here Insert Picture Description
find the incoming path, only this time a little faster browser test
Here Insert Picture Description
successful

Released four original articles · won praise 0 · Views 38

Guess you like

Origin blog.csdn.net/qq_43536831/article/details/104378857