Command Injection Proof of Concept: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
Zeile 1: Zeile 1:
 
=PHP Code=
 
=PHP Code=
 
<nowiki>
 
<nowiki>
<!DOCTYPE html>
+
<!DOCTYPE html>
<html>
+
<html>
 
         <body>
 
         <body>
 
                 <h2>PING</h2>
 
                 <h2>PING</h2>

Version vom 27. Juni 2021, 16:04 Uhr

PHP Code

<!DOCTYPE html> <html> <body> <h2>PING</h2> <form method="post"> <label for="fname">IP</label><br> <input type="text" name="ip"><br> <input type="submit" name="submit" value="submit"> </form> <br> <?php if(isset($_POST['submit'])){ $ip = $_POST['ip']; $cmd = 'ping -c 4 ' . $ip; $output = shell_exec($cmd); echo <pre>$output</pre>"; } ?> </body> </html> </code>