How to understand the recurrence of Thinkphp5.1.37-5.1.41 (latest version) deserialization vulnerability
In this issue, Xiaobian will bring you about how to understand Thinkphp 5.1.37 -5.1.41(the latest version) deserialization vulnerability recurrence. The article is rich in content and analyzed and described from a professional perspective. After reading this article, I hope you can gain something.
0x01 Introduction
Record the process of learning and understanding the anti-sequence vulnerability of thinkphp
0x02 Impact Version
5.1.37-5.1.41(Latest version)
0x03 Environment construction
1. composer create-project topthink/think=5.1.37 v5.1.37 (5.1.37-5.1.41 are available)
2、github:
https://github.com/top-think/think/releases
https://github.com/top-think/framework/releases
0x04 Bug recurrence
First add a deserialized entry
deserialize the input parameter in application\index\controller\index.php