Get the App
SLTechnology News&Howtos  ›  Network Security  › 

How to understand the recurrence of Thinkphp5.1.37-5.1.41 (latest version) deserialization vulnerability

Shulou Source: shulou.com Published: 2022-05-31 23:02:36 10月03日 Update

In this issue, Xiaobian will bring you about how to understand Thinkphp 5.1.37 -5.1.41(the latest version) deserialization vulnerability recurrence. The article is rich in content and analyzed and described from a professional perspective. After reading this article, I hope you can gain something.

0x01 Introduction

Record the process of learning and understanding the anti-sequence vulnerability of thinkphp

0x02 Impact Version

5.1.37-5.1.41(Latest version)

0x03 Environment construction

1. composer create-project topthink/think=5.1.37 v5.1.37 (5.1.37-5.1.41 are available)

2、github:

https://github.com/top-think/think/releases

https://github.com/top-think/framework/releases

0x04 Bug recurrence

First add a deserialized entry

deserialize the input parameter in application\index\controller\index.php

Tags: Methods sequences functions code objects properties versions vulnerabilities variables characters strings parameters data procedures analysis controls common forms filters primitive Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Microsoft Linux Huawei OPPO Reno macOS