漏洞描述 【漏洞对象】Thinkphp框架 【漏洞描述】Thinkphp框架的/index.php文件参数X-Forwarded-For存在sql注入,可造成信息数据泄露,攻击者可利用该漏洞执行SQL指令,甚至入侵服务器。
相关漏洞推荐 信呼OA index.php openkqjAction SQL 注入漏洞 POC CVE-2025-44136: MapTiler Tileserver-php v2.0 - Unauthenticated XSS POC CVE-2025-44137: MapTiler Tileserver-php v2.0 - Unauthenticated File Read POC generic-php-files: Generic PHP Backup Information Disclosure AbanteCart /index.php template 目录遍历漏洞(CVE-2025-50971) AbanteCart /index.php tmpl_id SQL 注入漏洞(CVE-2025-50972) POC 云课网校系统 /index/Exam/getExamImg 文件上传漏洞 PHPGurukul Employee Record Management System 代码注入漏洞 PHPJABBERS Restaurant Menu Maker Project 代码注入漏洞 NiuShop开源商城 /index.php SQL 注入漏洞(CNVD-2017-08412) ShowDoc /server/index.php?s=/api/adminUpdate/download 文件上传漏洞(CVE-2021-36440) php-livechat-uploadimg-html-upload: PHP LiveChat Upload thinkphp-30-rce: Thinkphp 3.0 RCE