Create CVE-2020-8644.md

add CVE-2020-8644
This commit is contained in:
Goby 2023-04-06 20:07:11 +08:00 committed by GitHub
parent f3f948aba4
commit e249f33a88
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

12
CVE-2020-8644.md Normal file
View File

@ -0,0 +1,12 @@
## playSMS 1.4.3 RCE (CVE-2020-8644)
| **Vulnerability** | **playSMS 1.4.3 RCE (CVE-2020-8644)** |
| :----: | :-----|
| **Chinese name** | playSMS 1.4.3 远程命令执行漏洞 (CVE-2020-8644) |
| **CVSS core** | 9.5 |
| **FOFA Query** (click to view the results directly)| [title=="playSMS"](https://fofa.info/result?qbase64=dGl0bGU9PSJwbGF5U01TIg%3D%3D) |
| **Number of assets affected** | 722 |
| **Description** | PlaySMS is a free and open source SMS gateway software. An input validation error vulnerability existed in PlaySMS versions prior to 1.4.3, which was caused by the program not sanitizing malicious strings. An attacker could exploit this vulnerability to execute arbitrary code. |
| **Impact** | An input validation error vulnerability existed in PlaySMS versions prior to 1.4.3, which was caused by the program not sanitizing malicious strings. An attacker could exploit this vulnerability to execute arbitrary code. |
![](https://s3.bmp.ovh/imgs/2023/04/03/70ee3365dd90c1a5.gif)