Skip to content

Instantly share code, notes, and snippets.

@ts0818
Created November 5, 2015 08:29
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save ts0818/43bd34d24c1881f3d7c8 to your computer and use it in GitHub Desktop.
Save ts0818/43bd34d24c1881f3d7c8 to your computer and use it in GitHub Desktop.
パーフェクトPHP コマンド実行攻撃(Command Injection)
<?php
/**
* このプログラムは脆弱性のサンプルです。
* 公開サーバに設置しないでください
*/
// 一覧を出力するディレクトリを$dir変数にセット
if (isset($_GET['dir']) === true) {
$dir = $_GET['dir'];
} else {
$dir = '/';
}
// ディレクトリ内のファイル一覧を出力
echo "<pre>";
system('ls -la ' . $dir);
echo "</pre>";
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment