Yii是YII团队的开发的一套基于组件、用于开发大型Web应用的高性能PHP框架。 Yii 2 2.0.52之前版本存在安全漏洞,该漏洞源于行为附加处理不当。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yiiframework | Yii | 2 ~ 2.0.52 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Yii2 PHP Framework before 2.0.52 is vulnerable to remote code execution via improper validation of the __class key in JSON behaviors. An attacker can instantiate arbitrary PHP classes and achieve RCE. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-58136.yaml | POC Details |
No comments yet