vendor:
Not mentioned
by:
AkkuS <Özkan Mustafa Akkus>, IHTeam
N/A
CVSS
N/A
Unauthenticated Remote Code Execution
Not mentioned
CWE
Product Name: Not mentioned
Affected Version From: Not mentioned
Affected Version To: Not mentioned
Patch Exists: Not mentioned
Related CWE: CVE-2020-
CPE: Not mentioned
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2020-21047/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2020-22219/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2020-22219/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2020-22218/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2020-19724/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2020-18839/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2020-22217/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2020-19726/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2020-22628/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2020-21047/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2020-22217/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2020-21710/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2020-22219/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2020-18651/, https://www.rapid7.com/db/vulnerabilities/alma_linux-cve-2020-22219/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2020-21890/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2020-18839/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2020-21490/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2020-19909/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2020-22628/, https://www.rapid7.com/db/?q=CVE-2020-&type=&page=2, https://www.rapid7.com/db/?q=CVE-2020-&type=&page=3, https://www.rapid7.com/db/?q=CVE-2020-&type=&page=4, https://www.rapid7.com/db/?q=CVE-2020-&type=&page=2
Platforms Tested: Unix
Not mentioned
TerraMaster TOS 4.2.06 – Unauthenticated Remote Code Execution
This module exploits a unauthenticated command execution vulnerability in TerraMaster TOS. The 'Event' parameter in 'include/makecvs.php' contains a vulnerability. 'filename' is executing command on system during '.csv' creation. In order to do this, it is not necessary to have a session in the application. Therefore an unathenticated user can execute the command on the system.
Mitigation:
Not mentioned