Cypht 2.12.2 之前的版本存在 PHP 对象注入漏洞,允许经过身份验证的攻击者通过构造的 PHP 对象图在退出处理程序的 back_query GET 参数中执行任意操作系统命令。攻击者可通过该参数传递 Base64 编码的序列化载荷,该载荷在被解码后会直接传入 unserialize() 函数,且未设置允许列表、签名校验或类型限制,从而可通过“小工具链”(gadget chain)利用实现以 Web 服务器进程权限执行远程代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet