References https://www.cnblogs.com/ichunqiu/p/10039579.html https://cws6.github.io/2019/03/24/phpcms2008%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/ https://blog.csdn.net/weixin_43263451/article/details/123664523 https://scanv.yunaq.com/news/5bfe801c678e00732a440db1.html https://developer.aliyun.com/article/673603 https://www.jianshu.com/p/6aa5e8520ee4 http://chybeta.github.io/2018/11/29/phpcms-2008-type-php-%E5%89%8D%E5%8F%B0%E4%BB%A3%E7%A0%81%E6%B3%A8%E5%85%A5getshell%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90/ https://nvd.nist.gov/vuln/detail/CVE-2018-19127 https://www.alibabacloud.com/blog/new-vulnerability-found-in-the-decade-old-phpcms-2008-can-lead-to-fresh-webshell-attacks_594275 https://github.com/advisories/GHSA-p498-q357-m3p7
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2020-10204: Sonatype Nexus Repository Manager 3 - Remote Code ExecutionPoCCVE-2026-17594: Sonatype Nexus Repository < 3.95.0 - Privilege Escalation via Repository Format MismatchPoCCVE-2026-48611: phpBB < 3.3.17 - Authentication BypassWordPress YARPP /includes/yarpp_pro_set_display_types.php 权限绕过漏洞 (CVE-2024-43919)PoCCVE-2026-46364: phpMyFAQ <= 4.1.1 - SQL InjectionPoCCVE-2026-6433: FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code ExecutionphpVMS /importer 未授权访问漏洞(CVE-2026-42569)智慧票务管理系统 /book/tickettypeindex.action 代码执行漏洞PoCphpjabbers-event-booking-xss: PHPJabbers Event Booking Calendar - Reflected XSSphpMyFAQ /api/captcha SQL 注入漏洞PoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization BypassphpVMS存在权限绕过漏洞(CVE-2026-42569)