add CVE-2020-24571

This commit is contained in:
tardc 2020-12-04 09:54:47 +08:00
parent 3921bf1f15
commit 360a08fbdd
2 changed files with 11 additions and 0 deletions

Binary file not shown.

After

Width:  |  Height:  |  Size: 406 KiB

View File

@ -0,0 +1,11 @@
# CVE-2020-24571 NexusDB path traversal
NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
**Affected version**: nexusdb < 4.50.23
**[FOFA](https://fofa.so/result?q=header%3D%22Server%3A+NexusDB%22&qbase64=aGVhZGVyPSJTZXJ2ZXI6IE5leHVzREIi&file=&file=) query rule**: header="Server: NexusDB"
# Demo
![](CVE-2020-24571.gif)