pluck-cms / pluck

Central repo for pluck cms

Home Page:http://www.pluck-cms.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Pluck-4.7.10-dev2 admin background exists a remote command execution vulnerability when uploading files

F1sh1001 opened this issue · comments

This vulnerability applies to php5.2. X

图片

After the installation is successful, go to the management background
图片

Then upload shell.php, It will be changed to shell.php.txt

图片

Then upload shell.php again

图片

Shell.php has not been changed to shell.php.txt

图片

then view shell.php

图片

As you state this is an issue with php 5.2.x this doesn't exist in php7. php5 is not longer supported by php (see https://www.php.net/supported-versions.php) and we cannot maintain versions which are no longer supported.

I have updated the minimal requirements to version 7 but it will work so I included a warning message that an insecure php version is used.

Will be in the next release