diff --git a/NexusDB/CVE-2020-24571/CVE-2020-24571.gif b/NexusDB/CVE-2020-24571/CVE-2020-24571.gif new file mode 100644 index 0000000..bf379ef Binary files /dev/null and b/NexusDB/CVE-2020-24571/CVE-2020-24571.gif differ diff --git a/NexusDB/CVE-2020-24571/README.md b/NexusDB/CVE-2020-24571/README.md new file mode 100644 index 0000000..34e5491 --- /dev/null +++ b/NexusDB/CVE-2020-24571/README.md @@ -0,0 +1,11 @@ +# CVE-2020-24571 NexusDB path traversal + +NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal. + +**Affected version**: nexusdb < 4.50.23 + +**[FOFA](https://fofa.so/result?q=header%3D%22Server%3A+NexusDB%22&qbase64=aGVhZGVyPSJTZXJ2ZXI6IE5leHVzREIi&file=&file=) query rule**: header="Server: NexusDB" + +# Demo + +![](CVE-2020-24571.gif) \ No newline at end of file