CVE-2024-50340: Symfony Profiler – Remote Access via Injected Arguments

CVE-2024-50340: Symfony Profiler - Remote Access via Injected Arguments-渗透云记 - 专注于网络安全与技术分享
CVE-2024-50340: Symfony Profiler – Remote Access via Injected Arguments
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-50340: Symfony Profiler – Remote Access via Injected Arguments

漏洞描述

symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享