CVE-2019-9082

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/thinkapp/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
Configurations

Configuration 1

cpe:2.3:a:thinkphp:thinkphp:*:*:*:*:*:*:*:*
cpe:2.3:a:opensourcebms:open_source_background_management_system:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:zzzcms:zzzphp:1.6.1:*:*:*:*:*:*:*

Information

Published : 2019-02-24 06:29

Updated : 2022-04-05 08:42


NVD link : CVE-2019-9082

Mitre link : CVE-2019-9082

Products Affected
No products.