4 ms·
The passwd file didn't help, it just showed him that he could retrieve arbitrary files via an open/improperly escaped PHP include(). His injected worked by cau
by erydo 17y ago
The passwd file didn't help, it just showed him that he could retrieve arbitrary files via an open/improperly escaped PHP include().
His injected worked by causing an error to be written to a log, and then reading that log back through the PHP include. The error that was logged contained an arbitrary string (the HTTP request, with the malicious PHP code), which was executed by the server.