启动环境

1
startup.bat

image-20230907231048142

​ 2. 访问抓包修改文件后缀

​ 可以显示phpinfo

image-20230915221602546

image-20230907231341384

Nginx 解析漏洞复现

1.开启环境

image-20230907231417121

image-20230907231433052

2.抓包修改文件后缀,类型以及内容头

image-20230907231444059

image-20230907231454645

上传成功

image-20230907231514105

使用蚁剑连接

image-20230907231534418

image-20230915221837364