A ThinkPHP 5.0.20 application, vulnerable to the ThinkPHP 5 routing RCE (5.0.22 and 5.1.29 fixed it): without forced routing, the controller name in the URL can name any class with its namespace, and call its methods with request parameters.
Pas commencéDockercommit 27a312fx86_64 · aarch64Secret
Exploit the ThinkPHP 5 routing flaw to run a command on the server.
Le brief de ce lab se trouve dans son dépôt.