mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 19:18:06 +02:00
712 B
712 B
CVE-2021-29378
Description
SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php.
POC
Reference
- https://gitee.com/pear-admin/Pear-Admin-Think/issues/I3DIEC
- https://gitee.com/pear-admin/Pear-Admin-Think/issues/I3DIEC