Cotonti 1.0.0 版本的 Comments 插件在将 GET 参数传递给 时,未对允许反序列化的类( )进行限制,这使得未经身份验证的攻击者能够实例化带有攻击者可控属性的任意 PHP 类。攻击者可以通过构造序列化负载(payload)触发 PHP 对象注入,进而利用小工具链(gadget chains)实现数据库操纵或代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet