Title: JSP ???????
1?????????????????????????????
File Uploading Shell
??????????????? ???????????? ?????????????????????
?????????????? http//www.yonok.ac.th
?.???????? ??????????? . ???????? 3 ??????? 2550
2????????????? (upload1.htm)
ltform actionupload1.php enctype"multipart/
form-data" methodpostgt ltinput typefile
nameufgt ltinput typesubmitgt lt/formgt
3????????????????? (upload1.php)
lt? if (isset(_FILES"uf""name")) nm
_FILES"uf""name" if(copy(_FILES"uf""tm
p_name","./".nm)) echo "upload process"
else echo "upload error" ?gt
????????? http//www.thaiall.com/php/indexo.html
4???????????????????????? (upload2.htm)
ltform actionupload2.php enctype"multipart/
form-data" methodpostgt ltinput typefile
nameufgt ltinput namenewnmgt ltinput
typesubmitgt lt/formgt
5????????????????? (upload2.php)
lt? if (isset(_FILES"uf""name")) nm
_REQUEST"newnm" if(copy(_FILES"uf""tmp_n
ame","./".nm)) echo "upload process"
else echo "upload error" ?gt
????????? http//www.thaiall.com/php/indexo.html
6????????????? (upload3.htm)
ltform actionupload3.php enctype"multipart/
form-data" methodpostgt ltinput typefile
nameuf1gt ltinput typefile nameuf2gt ltinput
typesubmitgt lt/formgt
7????????????????? (upload3.php)
lt? if (isset(_FILES"uf1""name")) nm
_FILES"uf1""name" if(copy(_FILES"uf1""
tmp_name","./".nm)) echo "upload 1
processltbrgt" nm _FILES"uf2""name"
if(copy(_FILES"uf2""tmp_name","./".nm))
echo "upload 2 processltbrgt" ?gt
????????? http//www.thaiall.com/php/indexo.html
8?????????? Shell_exec
lt? echo shell_exec("del x.jpg") ?gt