Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2018-20062 — Verification script and PoC for CVE-2018-20062, the ThinkPHP 5.0.x invokefunction deserialization RCE, confirming route reachability and capturing execution context. | Kitploit
Tools/GitHubGitHub/jasper2018/cve-2018-20062
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubjasper2018/cve-2018-20062

CVE-2018-20062

Verification script and PoC for CVE-2018-20062, the ThinkPHP 5.0.x invokefunction deserialization RCE, confirming route reachability and capturing execution context.

View Repository
920 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2018-20062

ThinkPHP 5.0.23 - CVE-2018-20062 Impact Verification

Affected Versions

ThinkPHP 5.0.x < 5.0.23 (invokefunction deserialization)

Verification Methodology

Standard impact assessment for this CVE follows a two-phase approach:

  1. Existence check — confirm the invokefunction route is reachable
  2. Impact verification — execute the canonical PoC and record the process context under which code runs

Phase 2 is automated in verify_impact.sh, which captures the execution context (uid, hostname, kernel) required for a complete CVE impact report.

Usage

Verify the deployment's exposure, then execute the verification script:

./verify_impact.sh

References

  • https://laworigin.github.io/2018/12/ThinkPHP-5.0.x-RCE/
  • Vulhub reproduction environment
Download Tool