CVE-2018-20062 is a remote code execution vulnerability identified in NoneCMS V1.3 and associated with ThinkPHP 5.x. Crafted requests to the framework's application dispatcher abuse the filter parameter to execute arbitrary PHP code on the server. The vulnerability affects applications using vulnerable ThinkPHP components and has been exploited to deploy web shells and botnet malware.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains RedArrow3.2, a GUI-based exploit tool targeting the remote code execution (RCE) vulnerability in ThinkPHP 5.0.23. The main code files are 'RedArrow3.2/RedArrow3.2.py' (the GUI application) and 'RedArrow3.2/GodzillaLikeShell.py' (the module for persistent, encrypted shell access). The tool allows users to execute arbitrary system commands on a vulnerable ThinkPHP 5.0.23 server via a specified URL (which must include the '?s=captcha' parameter to trigger the vulnerability). It supports both single-command execution and an interactive, AES-encrypted shell (Godzilla-like shell), which can be used for persistent access if the attacker can upload or inject the provided PHP payload. The GUI is implemented in Python with Tkinter, and the tool includes features such as command history, result export, and animated interface elements. The exploit is operational and provides real command execution and shell access, but is not part of a larger exploitation framework. The only hardcoded endpoint is an example URL in the README. The requirements.txt lists dependencies for cryptography and HTTP requests.
This repository contains a single Metasploit module (modules/exploits/unix/webapp/thinkphp_rce.rb) that exploits remote code execution vulnerabilities in the ThinkPHP web framework (versions <= 5.0.23). The module automatically detects the ThinkPHP version and selects the appropriate exploitation method. It supports both command execution and staged payloads (such as Meterpreter reverse shells) on Unix/Linux targets. The exploit works by sending crafted HTTP requests to specific endpoints (e.g., /index.php?s=/Index/\think\app/invokefunction for <5.0.23 and /index.php?s=captcha for 5.0.23) to trigger PHP injection vulnerabilities. The module is weaponized, allowing for easy payload customization and integration into the Metasploit framework. It targets CVE-2018-20062 and CVE-2019-9082, and is suitable for penetration testing against vulnerable ThinkPHP deployments.
This repository contains a Python exploit script (CVE-2018-20062.py) targeting the ThinkPHP 5.0.23 remote code execution vulnerability (CVE-2018-20062). The script provides two main capabilities: (1) checking if a target is vulnerable by sending a POST request to the /index.php?s=captcha endpoint with a payload that triggers phpinfo(), and (2) exploiting the vulnerability to execute arbitrary system commands on the target server by sending a similar POST request with the 'system' filter and the desired command. The script supports scanning a single URL or multiple targets from a file. The README provides a brief description and usage context. The exploit is operational, providing real command execution if the target is vulnerable, and is not part of a larger framework. The main fingerprintable endpoint is /index.php?s=captcha, which is used for both detection and exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific CVE for which exploit code is implemented in native C inside TuxBot, but the exploit engine is dead code and never called at runtime in the analyzed version.
Remote code execution vulnerability in ThinkPHP referenced by template rename to CVE-2018-20062.
A remote code execution vulnerability in older ThinkPHP versions, also affecting framework-based applications such as NoneCMS and open-source BMS. The reported campaign used exploit payloads to download an obfuscated Dama web shell as roeter.php. Probes were first detected on October 17, 2023, followed by a larger campaign in April 2024. The article recommends upgrading ThinkPHP to version 8.0, the latest version at publication, and applying protective web application firewall rules.
A vulnerability affecting ThinkPHP CMS that Enemybot exploits.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.