出现漏洞的文件为:abtest_admin.php
<?php require 'admin/functions.php'; if (isset($_GET['action'])) { include 'admin/' . $_GET['action'] . '.php'; } else { include 'admin/list_experiments.php'; } ?>
# PoC : localhost/wp-content/plugins/abtest/abtest_admin.php?action=[LFI]
评论 (0)