mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-05-05 10:16:59 +00:00
add CVE-2020-15920
This commit is contained in:
parent
d20e71a9d6
commit
7965bfa8ff
BIN
Mida_eFramework/CVE-2020-15920/CVE_2020_15920.gif
Normal file
BIN
Mida_eFramework/CVE-2020-15920/CVE_2020_15920.gif
Normal file
Binary file not shown.
After Width: | Height: | Size: 713 KiB |
11
Mida_eFramework/CVE-2020-15920/README.md
Normal file
11
Mida_eFramework/CVE-2020-15920/README.md
Normal file
@ -0,0 +1,11 @@
|
||||
# Mida eFramework ajaxreq.php RCE(CVE-2020-15920)
|
||||
|
||||
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.
|
||||
|
||||
**Affected Version**: ≤2.9.0
|
||||
|
||||
**FOFA query rule**: [body="eFramework.css" && body="MUP"](https://fofa.so/result?qbase64=Ym9keT0iZUZyYW1ld29yay5jc3MiICYmIGJvZHk9Ik1VUCI%3D)
|
||||
|
||||
# Demo
|
||||
|
||||

|
Loading…
x
Reference in New Issue
Block a user