← 문제 목록
고급
Linux
100P
PHP 보안 취약점: cgi.fix_pathinfo
공격자가 /uploads/photo.jpg/evil.php URL로 임의의 PHP 코드를 실행할 수 있습니다.
NGINX
server {
listen 80;
root /var/www/html;
location ~ \.php$ {
fastcgi_pass unix:/run/php/php-fpm.sock;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
include fastcgi_params;
}
}
1명 풀이 · 정답률 100%