0day/ThinkPHP/ThinkPHP_v5.0.10-v3.2.3
2017-11-23 19:35:23 +08:00
..
2017-11-23 19:30:53 +08:00
2017-11-23 19:35:23 +08:00
2017-11-23 19:34:45 +08:00

ThinkPHP 3.2.3 缓存漏洞

Usage:

    %2F%2F%0D%0A payload = //+回车

换行导致payload逃逸出注释而执行

Mr5m1th

修复

thinkphp\library\think\cache\driver\File.php

public function set($name, $value, $expire = null)方法

Mr5m1th