JoomlaÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-10

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Joomla 3.0.0-3.4.6


·ì϶¸ÅÊö


JoomlaÊÇÃÀ¹úOpen Source MattersÍŶӵÄÒ»Ì×ʹÓÃPHPºÍMySQL¿ª·¢µÄ¿ªÔ´¡¢¿çƽ̨µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£¡£¡£¡£


°²È«×êÑÐÈËÔ±¹«¿ªÁËÓ°ÏìJoomlaÄÚÈÝÖÎÀíϵͳÀϾɰ汾3.0.0ÖÁ3.4.6£¨ÔÚ2012Äê9ÔÂÄ©ÖÁ2015Äê12ÔÂÖÐÑ®°ä²¼£©µÄ·ì϶ÏêÇé¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÒ»¸öPHP¶ÔÏó×¢Èë·ì϶£¬£¬ £¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´Ðкó¹û¡£¡£¡£¡£¡£


Äܹ»Ê¹Óþ籾½øÐÐÑéÖ¤£ºÏÔʾVulnerableÖ¤Ã÷´æÔÚ·ì϶£¬£¬ £¬£¬£¬£¬¾ç±¾Á´½Ó£ºhttps://github.com/momika233/Joomla-3.4.6-RCE¡£¡£¡£¡£¡£



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


·ì϶ÑéÖ¤


EXP£ºhttps://www.exploit-db.com/exploits/47465¡£¡£¡£¡£¡£


½¨¸´½¨Òé


¹Ù·½ÒѾ­ÍƳö°²È«¸üУ¬£¬ £¬£¬£¬£¬Çë¸üÐÂÖÁ×îа汾3.9.12£ºhttps://downloads.joomla.org/¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.csdn.net/weixin_43886632/article/details/102461974