file_get_contents()文件包含漏洞,根据题目提示txt?尝试flag.txt
payload: ?ac=flags&fn=flag.txt
28.web8
原文:https://www.cnblogs.com/tqqnb/p/12080019.html