Path traversal in qdPM - CVE-2020-7246
Published: January 21, 2020 / Updated: September 29, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the users['photop_preview'] delete photo feature. A remote authenticated attacker can send a specially crafted HTTP request and read arbitrary files on the system, leading to arbitrary code execution.
Affected software
How to mitigate CVE-2020-7246
Links to Public Exploits and PoC-codes
- Exploit #8414 - qdPM 9.1 Authenticated Arbitrary PHP File Upload (RCE) (September 29, 2022)
- Exploit #8302 - SecAssignment (A Docker image vulnerable to CVE-2020-7246.) (August 28, 2022)
- Exploit #7894 - qdPM 9.1 - Remote Code Execution (RCE) (Authenticated) (v2) (May 26, 2022)
- Exploit #7070 - qdPM 9.1 - Remote Code Execution (RCE) (Authenticated) (November 25, 2021)
- Exploit #5801 - qdPM 9.1 - Remote Code Execution (June 17, 2021)
- Exploit #5757 - qdPM < 9.1 - Remote Code Execution (June 17, 2021)
- Exploit #5413 - qdPM9.1_Exploit (This is an exploit to automatically upload a PHP web shell to the qdPM 9.1 platform via the "upload a profile photo" feature. This method also bypasses the fix put into place from a previous CVE) (May 16, 2021)