ThinkPHP 5.0.23 (debug off), vulnerable to the 5.0.x request method RCE: the _method parameter lets a POST call any Request method, including __construct, which overwrites the filter list so that call_user_func runs a chosen function (system) on a chosen value.
Pas commencéDockercommit 8c89a26x86_64 · aarch64Secret
Exploit the ThinkPHP 5.0.23 _method RCE to run commands on the server and get a shell.
Le brief de ce lab se trouve dans son dépôt.