Description 漏洞影响文件:/base/post.php /base/appfile.php /base/appplue.php /base/appborder.phpPhpweb<=2.0.35
References https://www.o2oxy.cn/2582.html https://blog.csdn.net/weixin_44508748/article/details/105671332 https://github.com/jas502n/phpweb https://zone.ci/aliyun/ali_nonvd/259048.html https://avd.aliyun.com/detail?id=AVD-2023-1678770 https://forum.90sec.com/t/topic/679 https://forum.90sec.com/t/topic/775 https://www.getmonero.us/down/www.0-sec.org/0day/Phpweb/Phpweb%20%E5%89%8D%E5%8F%B0getshell.html https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/Phpweb/Phpweb%20%E5%89%8D%E5%8F%B0getshell/
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2026-48611: phpBB < 3.3.17 - Authentication BypassPoCCVE-2026-46364: phpMyFAQ <= 4.1.1 - SQL InjectionPoCCVE-2026-6433: FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code ExecutionphpVMS /importer 未授权访问漏洞(CVE-2026-42569)PoCphpjabbers-event-booking-xss: PHPJabbers Event Booking Calendar - Reflected XSSphpMyFAQ /api/captcha SQL 注入漏洞PoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization BypassphpVMS存在权限绕过漏洞(CVE-2026-42569)PoCCVE-2020-26935: phpMyAdmin < 5.0.3 - SQL InjectionPoCphp-prober-exposure: PHP Prober - ExposurePoCcakephp-debugkit-exposure: CakePHP - Debug Kit Toolbar ExposurePoCCVE-2025-69200: phpMyFAQ - Configuration Backup Disclosure