转:http://www.cgisecurity.com/lib/sips.html
Security Issues in Perl Scripts
By Jordan Dimov ([email protected])
Introduction
A programming language, by design, does not normally constitute a s ...……
use CGI;
use CGI qw/:standard/;
use Digest::MD5 qw(md5_hex);
my $query = CGI-amp;amp;gt;new(\amp;amp;amp;hook,$PREF_logfh);
my $filename = $query-amp;amp;gt;param('uploadname');
($filename,$file_ext ...……
Natas32:
打开后和natas31相似的界面,并且提示,这次您需要证明可以远程代码执行,Webroot中有一个二进制文件可以执行。
my $cgi = CGI-amp;amp;gt;new;
if ($cgi-amp;amp;gt;upload('file')) {
my $file = ...……