7 lines
240 B
Markdown
Raw Normal View History

2017-11-24 19:04:20 +08:00
# sugarCRM反序列化漏洞(对象注入漏洞)绕过__wakeup
2017-09-25 21:29:27 +08:00
2017-11-24 19:04:20 +08:00
### 影响版本 `SugarCRM <= 6.5.23 PHP5 < 5.6.25 PHP7 < 7.0.10`
2017-09-25 21:31:10 +08:00
2017-11-24 19:04:20 +08:00
### 修复建议:
2017-11-24 19:03:00 +08:00
`include/utils.php sugar_unserialize函数正则匹配修正为 /[oc]:[^:]*\d+:/i··`