PHP Exploit Chain

PHP 审计漏洞链组装方法论。当已完成各分类漏洞审计、需要评估多个漏洞组合利用的可行性时触发。 覆盖: 文件写入→文件包含→RCE 链、反序列化→敏感操作链、SQL 注入→文件写入链、 SSRF→内部服务链、信息泄露→权限提升链。同时包含 Composer 依赖 CVE 扫描方法。

wgpsec e39273f 5.3 KB Updated

File contents

wgpsec/aboutsecurity/tree/main/skills/code-audit/php/php-exploit-chain commit e39273f74d

Frequently asked questions

npx skillmds@latest add wgpsec/php-exploit-chain