656
VMScore

CVE-2020-7246

Published: 21/01/2020 Updated: 10/11/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 656
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A remote code execution (RCE) vulnerability exists in qdPM 9.1 and previous versions. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of .htaccess protection. NOTE: this issue exists because of an incomplete fix for CVE-2015-3884.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qdpm qdpm

Exploits

#!/usr/bin/python #------------------------------------------------------------------------------------- # Title: qdPM Webshell Upload + RCE Exploit (qdPMv91 and below) (CVE-2020-7246) # Author: Tobin Shields (@TobinShields) # # Description: This is an exploit to automatically upload a PHP web shell to # the qdPM platform via the "upload a pro ...
qdPM version 91 authenticated remote code execution exploit that leverages a path traversal ...
qdPM version 91 suffers from a remote code execution vulnerability ...
qdPM versions prior to 91 suffer from a remote shell upload vulnerability that allows for remote code execution ...

Github Repositories

This is an exploit to automatically upload a PHP web shell to the qdPM 9.1 platform via the "upload a profile photo" feature. This method also bypasses the fix put into place from a previous CVE

qdPM v91 Authenticated RCE Exploit This is an exploit to automatically upload a PHP web shell to the qdPM 91 platform via the "upload a profile photo" feature This method also bypasses the fix put into place from a previous CVE Vulnerability Information CVE: CVE-2020-7246 NVD Published Date: 01/21/2020 Base Score 88 (HIGH) Vulnerability Type Web Exploit

A Docker image vulnerable to CVE-2020-7246.

CVE-2020-7246 (qdPM 91) For educational purposes only See Reference for the details Run $ git clone githubcom/arafatansari/SecAssignmentgit $ cd SecAssignment $ docker build -t cve-assignment:ine $ docker run -it -p 80:80 cve-assignment:ine $ service apache2 start | service mysql start Exploit $ python Exploit/exploitpy -u

CVE-2020-7246 (qdPM 91) For educational purposes only See Reference for the details Run $ git clone githubcom/arafatansari/QDPMSECgit $ cd QDPMSEC $ docker build -t cve-assignment:ine $ docker run -it -p 80:80 cve-assignment:ine Installation Checking Environment Setting up SQL Server Create Admin login/password In ord

Sharing POC's of latest discovery

Public_Disclosure Sharing POC's of latest discovery Unauthenticated RCE in learnnowtelekomde/ Vulnerability – Insecure Deserialzation Vulnerability Vulnerability Description – Telerik UI for ASPNET (Version - 201631018) was being used by the application It suffers from a known vulnerability CVE-2019-18935 (Insecure Deserialization) Using basic fi