mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-03 21:18:06 +02:00
48 lines
2.0 KiB
Markdown
48 lines
2.0 KiB
Markdown
### [CVE-2020-16846](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16846)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://packetstormsecurity.com/files/160039/SaltStack-Salt-REST-API-Arbitrary-Command-Execution.html
|
|
- https://github.com/saltstack/salt/releases
|
|
|
|
#### Github
|
|
- https://github.com/0day404/vulnerability-poc
|
|
- https://github.com/0ps/pocassistdb
|
|
- https://github.com/20142995/Goby
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/ARPSyndicate/kenzer-templates
|
|
- https://github.com/ArrestX/--POC
|
|
- https://github.com/EdgeSecurityTeam/Vulnerability
|
|
- https://github.com/Elsfa7-110/kenzer-templates
|
|
- https://github.com/HimmelAward/Goby_POC
|
|
- https://github.com/KayCHENvip/vulnerability-poc
|
|
- https://github.com/Miraitowa70/POC-Notes
|
|
- https://github.com/Ostorlab/KEV
|
|
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
|
|
- https://github.com/SexyBeast233/SecBooks
|
|
- https://github.com/Threekiii/Awesome-POC
|
|
- https://github.com/Threekiii/Vulhub-Reproduce
|
|
- https://github.com/Z0fhack/Goby_POC
|
|
- https://github.com/bakery312/Vulhub-Reproduce
|
|
- https://github.com/d4n-sec/d4n-sec.github.io
|
|
- https://github.com/hamza-boudouche/projet-secu
|
|
- https://github.com/huimzjty/vulwiki
|
|
- https://github.com/jweny/pocassistdb
|
|
- https://github.com/merlinepedra/nuclei-templates
|
|
- https://github.com/merlinepedra25/nuclei-templates
|
|
- https://github.com/nomi-sec/PoC-in-GitHub
|
|
- https://github.com/sobinge/nuclei-templates
|
|
- https://github.com/soosmile/POC
|
|
- https://github.com/tzwlhack/Vulnerability
|
|
- https://github.com/vlrhsgody/CVE_Docker
|
|
- https://github.com/zomy22/CVE-2020-16846-Saltstack-Salt-API
|
|
|