CVE-2020-7699
HIGHexpress-fileupload < 1.1.8 - Denial of Service and Remote Code Execution via Corrupt HTTP Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-7699. PoCs published by zodiac12-pub.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2020-7699, demonstrating a prototype pollution vulnerability in express-fileupload combined with an RCE in ejs. The exploit uses a crafted HTTP request to pollute the prototype chain and execute arbitrary commands via Node.js child_process.
Description
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2020-7699, demonstrating a prototype pollution vulnerability in express-fileupload combined with an RCE in ejs. The exploit uses a crafted HTTP request to pollute the prototype chain and execute arbitrary commands via Node.js child_process.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H