Vulnerabilities
Vulnerable Software
Thinkphp:  >> Thinkphp  Security Vulnerabilities
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.
CVSS Score
8.8
EPSS Score
0.02
Published
2022-02-10
SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.
CVSS Score
9.8
EPSS Score
0.01
Published
2021-12-15
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.
CVSS Score
9.8
EPSS Score
0.011
Published
2021-12-06
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.
CVSS Score
9.8
EPSS Score
0.034
Published
2021-12-06
ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.
CVSS Score
9.8
EPSS Score
0.011
Published
2021-09-28
CVE-2019-9082
Known exploited
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
CVSS Score
8.8
EPSS Score
0.941
Published
2019-02-24
ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable.
CVSS Score
9.8
EPSS Score
0.004
Published
2018-10-21
ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI.
CVSS Score
9.8
EPSS Score
0.003
Published
2018-10-19
ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI.
CVSS Score
9.8
EPSS Score
0.003
Published
2018-10-19
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.
CVSS Score
9.8
EPSS Score
0.003
Published
2018-09-26


Contact Us

Shodan ® - All rights reserved