Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2022-44289

Disclosure Date: December 06, 2022 (last updated October 08, 2023)
Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.
Attacker Value
Unknown

CVE-2022-25481

Disclosure Date: March 21, 2022 (last updated April 23, 2024)
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.