CVE-2020-11819

CRITICAL

Rukovoditel 2.5.2 - Remote Code Execution via Language File Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2020-11819. PoCs published by coiffeur, danyx07.

AI-analyzed exploit summary This exploit leverages an arbitrary file upload vulnerability in Rukovoditel 2.6.1 to upload a malicious PHP file, then uses a Local File Inclusion (LFI) vulnerability to execute it, resulting in remote code execution (RCE). The script automates the process of uploading a reverse shell and triggering it via a crafted request.

Description

In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.

Exploits (3)

exploitdb WORKING POC
by coiffeur · bashwebappsphp
https://www.exploit-db.com/exploits/49238

This exploit leverages an arbitrary file upload vulnerability in Rukovoditel 2.6.1 to upload a malicious PHP file, then uses a Local File Inclusion (LFI) vulnerability to execute it, resulting in remote code execution (RCE). The script automates the process of uploading a reverse shell and triggering it via a crafted request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rukovoditel v2.6.1
Auth required
Prerequisites: valid session ID (SID) · access to the target application · netcat listener for reverse shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by danyx07 · pythonwebappsphp
https://www.exploit-db.com/exploits/48784

This exploit leverages CVE-2020-11819 to achieve remote code execution in Rukovoditel < 2.7.1 via authenticated file upload and local file inclusion. It supports two attack modes: session fixation (CVE-2020-15946) or direct credential-based authentication.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rukovoditel < 2.7.1
Auth required
Prerequisites: Authenticated session or session fixation vulnerability · Network access to target · PHP file upload capability
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by danyx07 · poc
https://github.com/danyx07/PoC-RCE-Rukovoditel

This is a functional PoC for CVE-2020-11819 and CVE-2020-15946, targeting Rukovoditel CMS versions 2.4.x to 2.6.1. It exploits session fixation and local file inclusion to achieve remote code execution via a reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rukovoditel CMS 2.4.1-2.7.1
Auth required
Prerequisites: Valid credentials or session fixation via victim interaction · Registration module enabled for session fixation attack
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://fatihhcelik.blogspot.com/2020/01/rukovoditel-rce-via.html

Scores

CVSS v3 9.8
EPSS 0.2678
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
rukovoditel/rukovoditel 2.5.2
Published Apr 16, 2020
Tracked Since Feb 18, 2026