mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 10:09:29 +02:00
46 lines
2.1 KiB
Markdown
46 lines
2.1 KiB
Markdown
### [CVE-2020-5405](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5405)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/ARPSyndicate/kenzer-templates
|
|
- https://github.com/DSO-Lab/pocscan
|
|
- https://github.com/Elsfa7-110/kenzer-templates
|
|
- https://github.com/Loneyers/SpringBootScan
|
|
- https://github.com/NorthShad0w/FINAL
|
|
- https://github.com/Secxt/FINAL
|
|
- https://github.com/SexyBeast233/SecBooks
|
|
- https://github.com/Tim1995/FINAL
|
|
- https://github.com/amcai/myscan
|
|
- https://github.com/apachecn-archive/Middleware-Vulnerability-detection
|
|
- https://github.com/ax1sX/SpringSecurity
|
|
- https://github.com/d4n-sec/d4n-sec.github.io
|
|
- https://github.com/dudek-marcin/Poc-Exp
|
|
- https://github.com/enomothem/PenTestNote
|
|
- https://github.com/huimzjty/vulwiki
|
|
- https://github.com/lovechinacoco/https-github.com-mai-lang-chai-Middleware-Vulnerability-detection
|
|
- https://github.com/merlinepedra/nuclei-templates
|
|
- https://github.com/merlinepedra25/nuclei-templates
|
|
- https://github.com/pen4uin/awesome-vulnerability-research
|
|
- https://github.com/pen4uin/vulnerability-research
|
|
- https://github.com/pen4uin/vulnerability-research-list
|
|
- https://github.com/shadowsock5/spring-cloud-config-starter
|
|
- https://github.com/shanyuhe/YesPoc
|
|
- https://github.com/sobinge/nuclei-templates
|
|
- https://github.com/tdtc7/qps
|
|
- https://github.com/threedr3am/learnjavabug
|
|
- https://github.com/zhibx/fscan-Intranet
|
|
- https://github.com/zisigui123123s/FINAL
|
|
|