CVE-2020-15568: TerraMaster TOS v4.1.24 RCE

CVE-2020-15568: TerraMaster TOS v4.1.24 RCE-渗透云记 - 专注于网络安全与技术分享
CVE-2020-15568: TerraMaster TOS v4.1.24 RCE
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-15568: Terramaster TOS v4.1.24 rce

漏洞描述

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享