← 문제 목록
고급 Linux 100P

PHP 보안 취약점: cgi.fix_pathinfo

공격자가 /uploads/photo.jpg/evil.php URL로 임의의 PHP 코드를 실행할 수 있습니다.
NGINX
server {
    listen 80;
    root /var/www/html;

    location ~ \.php$ {
        fastcgi_pass unix:/run/php/php-fpm.sock;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        include fastcgi_params;
    }
}

답변

로그인 후 제출하기
1명 풀이 · 정답률 100%