CVE-2020-10389
HIGHChadha PHPKB Standard Multi-Language 9 - Authenticated Remote Code Execution via Global Settings POST Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-10389. PoCs published by Antonio Cannito.
AI-analyzed exploit summary This exploit leverages an authenticated remote code execution vulnerability in PHPKB Multi-Language v9 by injecting a system command into the 'putdown_for_maintenance' parameter via the admin/save-settings.php endpoint. The exploit logs in as a superuser, sends malicious input, and retrieves the output from a configuration file.
Description
admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global settings.
Exploits (1)
This exploit leverages an authenticated remote code execution vulnerability in PHPKB Multi-Language v9 by injecting a system command into the 'putdown_for_maintenance' parameter via the admin/save-settings.php endpoint. The exploit logs in as a superuser, sends malicious input, and retrieves the output from a configuration file.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H