Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Pluck-4.7.10-dev2 admin background exists a remote command execution vulnerability when uploading files #84

Closed
F1sh1001 opened this issue Oct 21, 2019 · 1 comment

Comments

@F1sh1001
Copy link

This vulnerability applies to php5.2. X

图片

After the installation is successful, go to the management background
图片

Then upload shell.php, It will be changed to shell.php.txt

图片

Then upload shell.php again

图片

Shell.php has not been changed to shell.php.txt

图片

then view shell.php

图片

@BSteelooper
Copy link
Contributor

As you state this is an issue with php 5.2.x this doesn't exist in php7. php5 is not longer supported by php (see https://www.php.net/supported-versions.php) and we cannot maintain versions which are no longer supported.

I have updated the minimal requirements to version 7 but it will work so I included a warning message that an insecure php version is used.

Will be in the next release

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

2 participants