References https://pentest-tools.com/vulnerabilities-exploits/weiphp-50-sql-injection_22474 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-20300.yaml https://intel.enki-guard.com/vulnerability/CVE-2020-20300-weiphp-sql-injection https://y4er.com/posts/weiphp-exp-sql/ https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/WeiPHP/WeiPHP%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://nvd.nist.gov/vuln/detail/CVE-2020-20300 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/cms/WeiPHP5.0-bind_follow-SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://peiqi.wgpsec.org/wiki/cms/WeiPHP/WeiPHP5.0%20bind_follow%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.html https://cve.imfht.com/poc_detail/b2a6f37d088f6315204a03400819ba19e99d3082 https://gitee.com/zyun4/wei-php5.0/issues/ICWO0Y
Related Vulnerabilitiesweiphp-path-traversal: Weiphp Path TraversalPoCCVE-2020-20300: WeiPHP 5.0 - SQL InjectionPoCCNVD-2021-09693: WeiPHP5.0 任意用户Cookie伪造PoCweiphp3-sessionid-fileupload: WeiPHP3.0 session_id 任意文件上传漏洞CNVD-2020-68596: WeiPHP 5.0 - Path TraversalPoCCVE-2025-34045: WeiPHP 5.0 - Path TraversalWeiPHP 后台弱口令漏洞WeiPHP bind_follow CVE-2020-20300 SQL注入漏洞WeiPHP scan_callback 远程代码执行漏洞WeiPHP Notice/index接口处存在代码执行漏洞Weiphp存在SQL注入WeiPHP 微信开发平台 _send_by_group 文件 group_id 参数 SQL 注入漏洞