PHP-FusionÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-05-22·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12099£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º8.8
Ó°Ïì°æ±¾
PHP-Fusion 9.03.00
·ì϶¸ÅÊö
ÔÚphp fusion 9.03.00ÖУ¬edit_profile.phpÔÊÐíÔ¶³Ì¾¹ýÉí·ÝÑéÖ¤µÄÓû§Ö´ÐÐËÁÒâ´úÂ룬ÓÉÓÚincludes/dynamics/includes/form_fileinput.phpºÍincludes/classes/phpfusion/installer/lib/core.settings.incÔÚÉÏ´«avatarÆÚ¼äÃýÎó´¦ÖÃÁË¿ÉÖ´ÐÐÎļþ¡£
·ì϶ÑéÖ¤
EXP£ºhttps://www.exploit-db.com/exploits/46839¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://github.com/php-fusion/PHP-Fusion/commit/943432028b9e674433bb3f2a128b2477134110e6¡£
²Î¿¼Á´½Ó
https://www.pentest.com.tr/exploits/PHP-Fusion-9-03-00-Edit-Profile-Remote-
Code-Execution.html
https://www.exploit-db.com/exploits/46839


¾©¹«Íø°²±¸11010802024551ºÅ