SugarCRM v6.5.23 PHP反序列化 对象注入漏洞

Basic Fields

SSV ID:
SSV-92404
Find Time:
Unknown
Submit Time:
2016-09-12
Level:
Category:
代码执行
Component:
SugarCRM
(=6.5.23)
Author:
Unknown
Submitter:
Knownsec
CVE-ID:
Add
CNNVD-ID:
Add
CNVD-ID:
Add
ZoomEye Dork:
Add

Source

Detail

Contributor t1m30ff Got  0KB
Loading icon
have 0  exchange

PoC (pocsuite 插件) (pocsuite 插件)

Contributor Hcamael totally have   8KB
Login to exchange

log cherryowb bigcow hash whoam1 etc 17 Exchange

Reference Linking

Solutions

Temp Solutions

Unavailable Temp Solutions

Official Solution

Unavailable Official solution

Defense Solutions

Unavailable Defense Solutions

Popularity 6604
Need to bind phone before comment. Bind Now

All Comments (1)

  • 你好,用你的dockerfile构建的环境无法复现此漏洞,即是运行了poc demo,然而在custom/目录下并未生成1.php文件。。然后我觉得可能是权限不足,就chmod 777 -R custom/ ,但是依然没有成功,google搜索到可能是php.ini 禁止了跨目录写文件,但是我find / -name 'php.ini' 发现容器里没有这个文件。。最后我在Windows的phpstudy环境中复现成功,在自己的lamp云主机也复现成功,想请教你dockerfile生成镜像后是不是还需要配置点什么?
    1F

※Any content provided by this site, only to learn the code and services, not for illegal purposes