",".asmx",".cer",".aSp",".aSpx",".aSa",".aSax",".aScx",".aShx",".aSmx",".cEr",".sWf",".swf",".htaccess...if (move_uploaded_file($temp_file, $img_path)) {
$is_upload = true;
} else...;
}
} else {
$msg = '此文件类型不允许上传!'...;
}
} else {
$msg = UPLOAD_PATH . '文件夹不存在,请手工创建!'...,当上传到win机器上时又会将后面的.去掉,然后后缀就又会被还原成.php,这样就可以执行了,下面演示一下
首先上传1.php文件并抓包,在burp修改文件后缀名为.php.
image.png
测试链接