[CVE-2018-19277] PhpSpreadsheet 1.5.0 及以下版本——XXE 注入
bishopfox.com | 漏洞 | CVE-2018-19277 | #php | #vulnerability | #xxe | #phpspreadsheet | #cve-2018-19277 | #file-read
摘要
PhpSpreadsheet 1.5.0 及以下版本 XXE 注入(CVE-2018-19277):攻击者用 UTF-7 编码绕过外部实体检测,构造恶意 xlsx 文件读取服务器上的文件、口令与源码;1.5.1 版修复。
- 发布时间
- 收录时间
Skip to content