ThinkSNS开发的微博程序存在过滤不严

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 存在上传文件过滤不严漏洞!可直接上传ASP,PHP等网马后纂名的文件! ### 详细说明: 存在上传文件过滤不严,可直接上传危险后纂名文件! ### 漏洞证明: [<img src="https://images.seebug.org/upload/201304/11230734fd75c35f58c306c28d8ece3fbd82e040.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201304/11230734fd75c35f58c306c28d8ece3fbd82e040.jpg) [<img src="https://images.seebug.org/upload/201304/11230749344c79288a545911c5975ade0cbdedff.jpg" alt="2.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201304/11230749344c79288a545911c5975ade0cbdedff.jpg) [<img src="https://images.seebug.org/upload/201304/11230819acfa17b669e1dc87223bb5d36494de59.jpg" alt="3.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201304/11230819acfa17b669e1dc87223bb5d36494de59.jpg) [<img src="https://images.seebug.org/upload/201304/112308312af8830907cb94051d4380e538716209.jpg" alt="34.jpg" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息