(编辑:jimmy 日期: 2025/9/22 浏览:2)
命令注入
命令注入(Command Injection
),对一些函数的参数没有做过滤或过滤不严导致的,可以执行系统或者应用指令(CMD
命令或者"htmlcode">
<"whoami");"htmlcode"><"whoami");"htmlcode"><"whoami");"htmlcode"><"ipconfig"; exec($test,$array); print_r($array); "htmlcode"><"whoami");"htmlcode"><"htmlcode"><"htmlcode"><"ls"; $fp"r"); //popen打一个进程通道"htmlcode"><"ipconfig"; $array"pipe","r"),"pipe","w"),"pipe","w")"htmlcode">上一篇:PHP实现爬虫爬取图片代码实例下一篇:Git命令之分支详解