From fcefadd820d03eb2ed07dec14ef36595b09f0bd7 Mon Sep 17 00:00:00 2001 From: mcdruid Date: Tue, 26 Nov 2024 12:41:22 +0000 Subject: [PATCH 1/2] phpthumb/FD1 --- gadgetchains/phpThumb/FD/1/chain.php | 16 ++++++++++++++++ gadgetchains/phpThumb/FD/1/gadgets.php | 11 +++++++++++ 2 files changed, 27 insertions(+) create mode 100644 gadgetchains/phpThumb/FD/1/chain.php create mode 100644 gadgetchains/phpThumb/FD/1/gadgets.php diff --git a/gadgetchains/phpThumb/FD/1/chain.php b/gadgetchains/phpThumb/FD/1/chain.php new file mode 100644 index 00000000..05689b90 --- /dev/null +++ b/gadgetchains/phpThumb/FD/1/chain.php @@ -0,0 +1,16 @@ +tempFilesToDelete[] = $tempFileToDelete; + } + +} From d4ed546a6691fb57f674949bd2ddf9deda77214d Mon Sep 17 00:00:00 2001 From: mcdruid Date: Tue, 26 Nov 2024 15:06:31 +0000 Subject: [PATCH 2/2] remove lower bound of version range --- gadgetchains/phpThumb/FD/1/chain.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gadgetchains/phpThumb/FD/1/chain.php b/gadgetchains/phpThumb/FD/1/chain.php index 05689b90..3280ec32 100644 --- a/gadgetchains/phpThumb/FD/1/chain.php +++ b/gadgetchains/phpThumb/FD/1/chain.php @@ -4,7 +4,7 @@ class FD1 extends \PHPGGC\GadgetChain\FileDelete { - public static $version = 'v1.7.12 <= v1.7.22'; + public static $version = '<= v1.7.22'; public static $vector = '__destruct'; public static $author = 'mcdruid'; public static $information = 'Fixed by https://github.com/JamesHeinrich/phpThumb/pull/226';