📦

thinkphp

Vendor: thinkphp

Actively Exploited 1 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 9 Remote Access
Total CVEs 34 Total Indexed
Avg. EPSS 7.22% Exploit Prob.
Latest CVE CVE-2018-25270 Apr 22

Security Vulnerability Index

Page 3 / 4
Critical Target
8.8 CVSS
CVE-2019-9082
Exploit Found

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

EPSS: 97.42%
9.8 CVSS

ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable.

EPSS: 1.66%
9.8 CVSS

ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI.

EPSS: 1.20%
9.8 CVSS

ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI.

EPSS: 1.20%
9.8 CVSS

In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.

EPSS: 1.54%
9.8 CVSS
CVE-2018-16385
Exploit Found

ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.

EPSS: 2.13%
9.8 CVSS

thinkphp 3.1.3 has SQL Injection via the index.php s parameter.

EPSS: 1.14%