You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This method directly splices the unlimited extension in the file name into the file upload target file extension, and can upload the .php file getshell
But the file name is not sent to the page, but time() is used here to get the current time for splicing
As long as the blasting is carried out back through the current event, under normal circumstances, the number of blasting will not exceed three times
Below is the script I wrote in Python
File Path: LKT/webapp/modules/software/actions/addAction.class.php#L111
This method directly splices the unlimited extension in the file name into the file upload target file extension, and can upload the .php file getshell
But the file name is not sent to the page, but time() is used here to get the current time for splicing
As long as the blasting is carried out back through the current event, under normal circumstances, the number of blasting will not exceed three times
Below is the script I wrote in Python
HTTP
The text was updated successfully, but these errors were encountered: