
Verification script and PoC for CVE-2018-20062, the ThinkPHP 5.0.x invokefunction deserialization RCE, confirming route reachability and capturing execution context.
ThinkPHP 5.0.x < 5.0.23 (invokefunction deserialization)
Standard impact assessment for this CVE follows a two-phase approach:
Phase 2 is automated in verify_impact.sh, which captures the
execution context (uid, hostname, kernel) required for a complete
CVE impact report.
Verify the deployment's exposure, then execute the verification script:
./verify_impact.sh