🔙 목록으로 돌아가기

CVE-2020-8644: playSMS <1.4.3 - Remote Code Execution

TitleplaySMS <1.4.3 - Remote Code Execution
Authordbrwsky
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows an attacker to execute arbitrary code on the target system.
RemediationUpgrade playSMS to version 1.4.4 or later to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.92716
CVE IDCVE-2020-8644
CWE IDCWE-94
Tags cve cve2020 unauth kev packetstorm ssti playsms rce vkev vuln

🔍 Vulnerability Description

PlaySMS before version 1.4.3 is susceptible to remote code execution because it double processes a server-side template.

🌐 HTTP Request

GET /index.php?app=main&inc=core_auth&route=login HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 14092.77.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.107 Safari/537.36
Connection: close
Origin: http://www.victim.com
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8644.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-8644.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A