mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-01 23:31:36 +02:00
18 lines
811 B
Markdown
18 lines
811 B
Markdown
### [CVE-2020-14028](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14028)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. By leveraging a path traversal vulnerability in the Autoreply module's Script Name, an attacker may write to or overwrite arbitrary files, with arbitrary content, usually with NT AUTHORITY\SYSTEM privileges.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-14028-Arbitary%20File%20Write-Ozeki%20SMS%20Gateway
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|