Exploitation Summary
CVE-2024-44902 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including fru1ts, KrE80r.
AI-analyzed exploit summary This repository provides a functional exploit for CVE-2024-44902, a deserialization vulnerability in ThinkPHP v6.1.3 to v8.0.4. It includes a detailed payload generation script and demonstrates how to achieve RCE by exploiting the Memcached driver's deserialization chain.
Description
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
Exploits (2)
This repository provides a functional exploit for CVE-2024-44902, a deserialization vulnerability in ThinkPHP v6.1.3 to v8.0.4. It includes a detailed payload generation script and demonstrates how to achieve RCE by exploiting the Memcached driver's deserialization chain.
This repository provides a fully functional Dockerized environment for CVE-2024-44902, a critical insecure deserialization vulnerability in ThinkPHP 6.1.3-8.0.4. It includes vulnerable endpoints (`/api/sync` and `/api/import`) that directly unserialize user-controlled input, enabling RCE when the Memcached extension is present.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H