顶想信息科技 ThinkPHP是中国顶想信息科技公司的一套基于PHP的、开源的、轻量级Web应用程序开发框架。 ThinkPHP Framework v5.0.24 存在安全漏洞,该漏洞源于没有配置 PATHINFO 参数。攻击者可以从 index.php 访问所有系统环境参数。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ThinkPHP 5.0.24 is susceptible to information disclosure. This version was configured without the PATHINFO parameter. This can allow an attacker to access all system environment parameters from index.php, thereby possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25481.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-39384 | DWSurvey 代码问题漏洞 | |
| CVE-2021-42194 | 赞赞网络科技 EyouCms 代码问题漏洞 | |
| CVE-2021-39383 | DWSurvey 代码注入漏洞 | |
| CVE-2020-26008 | ShopXO 代码问题漏洞 | |
| CVE-2020-26007 | ShopXO 代码问题漏洞 | |
| CVE-2022-25462 | Yafu 安全漏洞 | |
| CVE-2022-26555 | Eova 跨站脚本漏洞 | |
| CVE-2022-26246 | TMS 跨站脚本漏洞 | |
| CVE-2022-26247 | TMS 安全漏洞 | |
| CVE-2022-25464 | DoraCMS 跨站脚本漏洞 | |
| CVE-2021-44345 | Ltd One Card Integrated Management SystemSQL注入漏洞 | |
| CVE-2022-24125 | Bandai Namco FromSoftware Dark Souls III 安全漏洞 |
'
test'
1