null;
if (isset($_POST['submit'])) {
if (file_exists($UPLOAD_ADDR)) {
$deny_ext = array('.asp...;
}
}
从源码中我们可以看到,当前禁止了asp aspx php jsp等常见的后缀名。此时我们用BURP截包改包即可。
只需要将后缀名php改为phtml即可。...image.png
如图,成功上传,获得shell
image.png
更另类的文件绕过
先看源码
$is_upload = false;
$msg = null;
if (isset($_POST['...",".aspx",".asa",".asax",".ascx",".ashx",".asmx",".cer",".aSp",".aSpx",".aSa",".aSax",".aScx",".aShx"...将php改为phP或者pHP即大小写组合。