GobyVuls/URVE/CVE-2020-29552
2021-08-14 19:01:21 +08:00
..
2021-08-14 19:01:06 +08:00

URVE 2020.03.24 RCE (CVE-2020-29552)

An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0;powershell+-c+" substring, it is possible to execute a Powershell command and redirect its output to a file under the web root.

FOFA query rule: body="URVE"

Demo

URVE_2020_03_24_RCE_CVE_2020_29552