File inclusions (LFI, RFI)
PHP settings
String termination
include("path/ + $GET_['FILE] + ".php);1. Null byte poisoning
filename.txt%002. Query parameter
Local File Inclusion (LFI)
Log file poisoning
Example
Read source files
Remote File Inclusion (RFI)
Last updated