<?phpunlink ($evil_var);fwrite ($fp, $evil_var);system ($evil_var);exec ($evil_var);?>
<?php$username = $_POST['user_submitted_name'];$homedir = "/home/$username";$file_to_delete = "$userfile";unlink ("$homedir/$userfile");echo "$file_to_delete has been deleted!";?>
<?php$username = $_SERVER['REMOTE_USER'];$homedir = "/home/$username"; if (!ereg('^[^./][^/]*$', $userfile))die('bad filename'); if (!ereg('^[^./][^/]*$', $username))die('bad username');?>
2/2 首页 上一页 1 2