Yii是Yii团队的Yii是Yii团队开发的一套基于组件、用于开发大型Web应用的高性能PHP框架。 Yii2,2.0.38之前版本中存在代码问题漏洞。该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | 几条关于CVE-2020-15148(yii2反序列化)的绕过 | https://github.com/Maskhe/CVE-2020-15148-bypasses | POC Details |
| 2 | cve-2020-15148 | https://github.com/0xkami/cve-2020-15148 | POC Details |
| 3 | Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-15148.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet