CVE-2020-7882
HIGH EXPLOITEDHancom AnySign4PC - Path Traversal and Arbitrary File Deletion via getPFXFolderList Parameter
Title source: llmExploitation Summary
CVE-2020-7882 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including HORKimhab.
AI-analyzed exploit summary The repository claims to be an exploit for CVE-2020-7882 but contains no actual exploit code, technical details, or proof-of-concept. It only includes a README with donation requests, setup instructions, and legal disclaimers.
Description
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
Exploits (1)
The repository claims to be an exploit for CVE-2020-7882 but contains no actual exploit code, technical details, or proof-of-concept. It only includes a README with donation requests, setup instructions, and legal disclaimers.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N