Lyther/VulnDiscover

Lyther/VulnDiscover

Releases0
Stars3
Vulnerability discovery history and log

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.