CVE-2020-35476: OpenTSDB 2.4.0 Remote Code Execution

CVE-2020-35476: OpenTSDB 2.4.0 Remote Code Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2020-35476: OpenTSDB 2.4.0 Remote Code Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-35476: OpenTSDB 2.4.0 Remote Code Execution

漏洞描述

A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java attempted to prevent command injections by blocking backticks but this is insufficient.)

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享