漏洞描述 FrozenNode Laravel-Administrator是一款用于Laravel框架的管理界面生成器。 FrozenNode Laravel-Administrator 5.0.12及之前版本中存在代码问题漏洞。攻击者可借助文件上传功能利用该漏洞绕过安全限制,上传恶意文件,进而执行PHP代码。
相关漏洞推荐 Astro Web Framework Cloudflare /_image 服务器端请求伪造漏洞(CVE-2025-58179) Spring Framework路径遍历漏洞(CVE-2024-38819) Vmware Spring Framework 逻辑缺陷漏洞 OpenOrange Business Framework访问控制错误漏洞(CVE-2024-42048) POC CVE-2020-0646: Microsoft .NET Framework - Remote Code Execution POC spring4shell-CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+ POC CVE-2016-6601: ZOHO WebNMS Framework <5.2 SP1 - Local File Inclusion POC CVE-2017-1000163: Phoenix Framework - Open Redirect POC CVE-2017-16894: Laravel <5.5.21 - Information Disclosure POC CVE-2018-1271: Spring MVC Framework - Local File Inclusion POC CVE-2020-15227: Nette Framework - Remote Code Execution POC CVE-2020-15920: Mida eFramework <=2.9.0 - Remote Command Execution POC CVE-2020-36708: WordPress Epsilon Framework Themes <=2.4.8 - Remote Code Execution