Files
CVEs-PoC/2020/CVE-2020-0646.md
T
2024-05-25 21:48:12 +02:00

88 lines
10 KiB
Markdown

### [CVE-2020-0646](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0646)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.0&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.6.2%2F4.7%2F4.7.1%2F4.7.2%20on%20Windows%2010%20Version%201607%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.6.2%2F4.7%2F4.7.1%2F4.7.2%20on%20Windows%2010%20Version%201607%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.6.2%2F4.7%2F4.7.1%2F4.7.2%20on%20Windows%20Server%202016%20%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.6.2%2F4.7%2F4.7.1%2F4.7.2%20on%20Windows%20Server%202016&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.1%2F4.7.2%20on%20Windows%2010%20Version%201709%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.1%2F4.7.2%20on%20Windows%2010%20Version%201709%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%2010%20Version%201803%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%2010%20Version%201803%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%2010%20Version%201809%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%2010%20Version%201809%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%2010%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%2010%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%20Server%202019%20%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%20Server%202019&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%20Server%2C%20version%201803%20%20(Server%20Core%20Installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%2010%20Version%201809%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%2010%20Version%201809%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%2010%20Version%201903%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%2010%20Version%201903%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%2010%20Version%201909%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%2010%20Version%201909%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%20Server%202019%20%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%20Server%202019&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%20Server%2C%20version%201903%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%20Server%2C%20version%201909%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5.1&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.5.2&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.6%2F4.6.1%2F4.6.2%2F4.7%2F4.7.1%2F4.7.2&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.6&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.6.2%2F4.7%2F4.7.1%2F4.7.2&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201607%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201607%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201709%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201709%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201803%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201803%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%207%20for%2032-bit%20Systems%20Service%20Pack%201&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%207%20for%20x64-based%20Systems%20Service%20Pack%201&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%208.1%20for%2032-bit%20systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%208.1%20for%20x64-based%20systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20RT%208.1&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202008%20R2%20for%20x64-based%20Systems%20Service%20Pack%201%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202008%20R2%20for%20x64-based%20Systems%20Service%20Pack%201&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202012%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202012%20R2%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202012%20R2&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202012&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202016%20%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202016&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%2C%20version%201803%20%20(Server%20Core%20Installation)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Remote%20Code%20Execution&color=brighgreen)
### Description
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
### POC
#### Reference
- http://packetstormsecurity.com/files/156930/SharePoint-Workflows-XOML-Injection.html
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Amar224/best_google_dorks_tool
- https://github.com/Ashadowkhan/BigBountyRecontoolsexe
- https://github.com/H4cksploit/bug-bounty-recon
- https://github.com/NAVIN-HACSOCIETY/AdrishyaReconDorker
- https://github.com/Ostorlab/KEV
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
- https://github.com/PreemptiveCyberSec/BigBountyRecon
- https://github.com/SexyBeast233/SecBooks
- https://github.com/Th3l0newolf/AdvanceRecon-Dorks
- https://github.com/Vignesh2712/BigBountyRecon
- https://github.com/Viralmaniar/BigBountyRecon
- https://github.com/aftabkhan25/Tool2
- https://github.com/kartikhunt3r/AdrishyaReconDorker
- https://github.com/lnick2023/nicenice
- https://github.com/michael101096/cs2020_msels
- https://github.com/preemptive-cyber-security/BigBountyRecon
- https://github.com/qazbnm456/awesome-cve-poc
- https://github.com/scrumfox/BugBountyReconNet
- https://github.com/xbl3/awesome-cve-poc_qazbnm456