References https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-20300.yaml https://nvd.nist.gov/vuln/detail/CVE-2020-20300 https://www.cve.org/CVERecord?id=CVE-2020-20300 https://pentest-tools.com/vulnerabilities-exploits/weiphp-50-sql-injection_22474 https://peiqi.wgpsec.org/wiki/cms/WeiPHP/WeiPHP5.0%20bind_follow%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.html https://www.cnblogs.com/0kooo-yz/p/18334239 https://y4er.com/posts/weiphp-exp-sql/ https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/cms/WeiPHP5.0-bind_follow-SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.saury.net/878.html https://www.ddpoc.com/DVB-2023-4637.html
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2026-48611: phpBB < 3.3.17 - Authentication BypassPoCCVE-2026-46364: phpMyFAQ <= 4.1.1 - SQL InjectionPoCCVE-2026-6433: FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code ExecutionphpVMS /importer 未授权访问漏洞(CVE-2026-42569)PoCphpjabbers-event-booking-xss: PHPJabbers Event Booking Calendar - Reflected XSSphpMyFAQ /api/captcha SQL 注入漏洞PoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization BypassphpVMS存在权限绕过漏洞(CVE-2026-42569)PoCCVE-2020-26935: phpMyAdmin < 5.0.3 - SQL InjectionPoCphp-prober-exposure: PHP Prober - ExposurePoCcakephp-debugkit-exposure: CakePHP - Debug Kit Toolbar ExposurePoCCVE-2025-69200: phpMyFAQ - Configuration Backup Disclosure