CVE‑2025‑3515 — Contact Form 7 的多文件拖放上传插件
drag‑and‑drop‑multiple‑file‑upload‑contact‑form‑7 ≤1.3.8.9 版本可实现任意文件上传,允许上传 .phar 文件,从而在 Apache+mod_php 环境下导致远程代码执行 :contentReference[oaicite:29]{index=29}。该工具使用 Python 3 编写,利用检查器检测已安装的插件,然后进行漏洞利用。 Telegram:https://t.me/Professor6T9 团队 Telegram:https://t.me/TeamAnonForce6T9