,.aspx,.php,.jsp后缀文件!...;
}
} else {
$msg = '不允许上传.asp,.aspx,.php,.jsp后缀文件!'...;
}
}
逻辑大致是识别上传文件的类型 并查看是否是'.asp','.aspx','.php','.jsp'中的一个,否则不允许上传
bypass
尝试使用和php一样解析效果的后缀名,如php3...",".aspx",".asa",".asax",".ascx",".ashx",".asmx",".cer",".aSp",".aSpx",".aSa",".aSax",".aScx",".aShx"...",".aspx",".asa",".asax",".ascx",".ashx",".asmx",".cer",".aSp",".aSpx",".aSa",".aSax",".aScx",".aShx"