cnvd-2018-24942
cnvd
Description
ThinkPHP是由上海顶想信息科技有限公司开发维护的MVC结构的开源PHP框架。 thinkphp5存在远程代码执行漏洞。该漏洞由于框架对控制器名未能进行足够的检测,攻击者利用该漏洞对目标网站进行远程命令执行攻击。
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"description": "ThinkPHP是由上海顶想信息科技有限公司开发维护的MVC结构的开源PHP框架。\n\nthinkphp5存在远程代码执行漏洞。该漏洞由于框架对控制器名未能进行足够的检测,攻击者利用该漏洞对目标网站进行远程命令执行攻击。",
"discovererName": "thinkphp团队",
"formalWay": "用户可参考如下供应商提供的安全公告获得补丁信息:\r\nhttps://blog.thinkphp.cn/869075",
"isEvent": "通用软硬件漏洞",
"number": "CNVD-2018-24942",
"openTime": "2018-12-11",
"patchDescription": "ThinkPHP是由上海顶想信息科技有限公司开发维护的MVC结构的开源PHP框架。\r\n\r\nthinkphp5存在远程代码执行漏洞。该漏洞由于框架对控制器名未能进行足够的检测,攻击者利用该漏洞对目标网站进行远程命令执行攻击。目前,供应商发布了安全公告及相关补丁信息,修复了此漏洞。",
"patchName": "ThinkPHP5远程代码执行漏洞的补丁",
"products": {
"product": [
"上海顶想信息科技有限公司 ThinkPHP 5.*,<5.1.31",
"上海顶想信息科技有限公司 ThinkPHP <=5.0.23"
]
},
"referenceLink": "https://blog.thinkphp.cn/869075",
"serverity": "高",
"submitTime": "2018-12-11",
"title": "ThinkPHP5远程代码执行漏洞"
}