B2 Evolution CMS 6.7.8 至 7.2.5 版本中存在对 CVE-2016-8901 的修复不完整问题。其中, 函数中的序列化数组对象检查无法拒绝包含负整数数组键的负载。 未认证的 attackers 可以通过向 发送精心构造的 POST 请求,提交由攻击者构造的已序列化 PHP 对象,从而绕过验证并到达 函数,实例化具有攻击者选定属性的任意 PHP 对象。如果存在合适的 POP 小工具链(POP gadget chains),则可能导致代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| b2evolution | b2evolution CMS | 6.7.8≤ 7.2.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| b2evolution | b2evolution CMS | 6.7.8 ~ 7.2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet