CVE-2020-29597
CRITICAL EXPLOITED NUCLEIIncomCMS 2.0 - Unauthenticated Unrestricted File Upload via modules/uploader/showcase/script.php
Title source: llmExploitation Summary
CVE-2020-29597 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including MoeAlBarbari. A Nuclei detection template is also available.
AI-analyzed exploit summary This HTML form exploits an insecure file upload vulnerability in IncomCMS 2.0 by allowing arbitrary file uploads to a specific endpoint. The vulnerability can lead to remote code execution if the uploaded file is a malicious script.
Description
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.
Exploits (1)
This HTML form exploits an insecure file upload vulnerability in IncomCMS 2.0 by allowing arbitrary file uploads to a specific endpoint. The vulnerability can lead to remote code execution if the uploaded file is a malicious script.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H