cnvd-2018-24942

cnvd
Description

ThinkPHP是由上海顶想信息科技有限公司开发维护的MVC结构的开源PHP框架。 thinkphp5存在远程代码执行漏洞。该漏洞由于框架对控制器名未能进行足够的检测,攻击者利用该漏洞对目标网站进行远程命令执行攻击。

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "description": "ThinkPHP是由上海顶想信息科技有限公司开发维护的MVC结构的开源PHP框架。\n\nthinkphp5存在远程代码执行漏洞。该漏洞由于框架对控制器名未能进行足够的检测,攻击者利用该漏洞对目标网站进行远程命令执行攻击。",
  "discovererName": "thinkphp团队",
  "formalWay": "用户可参考如下供应商提供的安全公告获得补丁信息:\r\nhttps://blog.thinkphp.cn/869075",
  "isEvent": "通用软硬件漏洞",
  "number": "CNVD-2018-24942",
  "openTime": "2018-12-11",
  "patchDescription": "ThinkPHP是由上海顶想信息科技有限公司开发维护的MVC结构的开源PHP框架。\r\n\r\nthinkphp5存在远程代码执行漏洞。该漏洞由于框架对控制器名未能进行足够的检测,攻击者利用该漏洞对目标网站进行远程命令执行攻击。目前,供应商发布了安全公告及相关补丁信息,修复了此漏洞。",
  "patchName": "ThinkPHP5远程代码执行漏洞的补丁",
  "products": {
    "product": [
      "上海顶想信息科技有限公司 ThinkPHP 5.*,<5.1.31",
      "上海顶想信息科技有限公司 ThinkPHP <=5.0.23"
    ]
  },
  "referenceLink": "https://blog.thinkphp.cn/869075",
  "serverity": "高",
  "submitTime": "2018-12-11",
  "title": "ThinkPHP5远程代码执行漏洞"
}
View JSON API Download JSON