CVE-2020-1809
published 2020-05-29CVE-2020-1809: HUAWEI Mate 10 smartphones with versions earlier than 10.0.0.143(C00E143R2P4) have an information disclosure vulnerability. The attacker could wake up voice…
PriorityP417medium4.6CVSS 3.1
AVPACLPRNUINSUCHINAN
EPSS
0.24%
14.3th percentile
HUAWEI Mate 10 smartphones with versions earlier than 10.0.0.143(C00E143R2P4) have an information disclosure vulnerability. The attacker could wake up voice assistant then do a series of crafted voice operation, successful exploit could allow the attacker read certain files without unlock the phone leading to information disclosure.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | huawei_mate_10 | — | — |
| huawei | mate_10_firmware | < 10.0.0.143\(c00e143r2p4\) | 10.0.0.143\(c00e143r2p4\) |
| msrc | microsoft_net_framework_2.0_service_pack_2 | — | — |
| msrc | microsoft_net_framework_3.5 | — | — |
| msrc | microsoft_net_framework_3.5.1 | — | — |
| msrc | microsoft_net_framework_3.5_and_4.7.2 | — | — |
| msrc | microsoft_net_framework_3.5_and_4.8 | — | — |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc7.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cr94-qhhf-h959: HUAWEI Mate 10 smartphones with versions earlier than 10
ghsa_unreviewed·2022-05-24
CVE-2020-1809 [LOW] CWE-200 GHSA-cr94-qhhf-h959: HUAWEI Mate 10 smartphones with versions earlier than 10
HUAWEI Mate 10 smartphones with versions earlier than 10.0.0.143(C00E143R2P4) have an information disclosure vulnerability. The attacker could wake up voice assistant then do a series of crafted voice operation, successful exploit could allow the attacker read certain files without unlock the phone leading to information disclosure.
Microsoft
.NET Framework Remote Code Execution Vulnerability
vendor_msrc·2020-08-11·CVSS 7.8
CVE-2020-1046 [HIGH] .NET Framework Remote Code Execution Vulnerability
.NET Framework Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system.
To exploit the vulnerability, an attacker would need to be able to upload a specially crafted file to a web application.
The security update addresses the vulnerability by correcting how .NET Framework processes input.
FAQ: Why are there two Security Updates for Windows 10 version 1809 and Windows Server 2019?
Both updates address this vulnerability in Microsoft .NET Framework 3.5. However, Windows 10 version 1809 or Windows Server 2019 has either .NET Framework 4.7.2 or .NET Framework 4.8 installed in addition to .NET Framework 3.5. Th
No detection rules found.
Exploit-DB
Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
exploitdb·2020-10-20·CVSS 8.8
CVE-2020-25760 [HIGH] Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
---
# Title: Visitor Management System in PHP 1.0 - Authenticated SQL Injection
# Exploit Author: Rahul Ramkumar
# Date: 2020-09-16
# Vendor Homepage: https://projectworlds.in
# Software Link: https://projectworlds.in/wp-content/uploads/2020/07/Visitor-Management-System-in-PHP.zip
# Version: 1.0
# Tested On: Windows 10 Enterprise 1809 (x64_86) + XAMPP 7.2.33-1
# CVE: CVE-2020-25760
# Description
The file front.php does not perform input validation on the 'rid' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.
Note: This exploit can work pre-authentication as well, but need to change the 302 Response to 200 using an intercept tool. It should be pretty straight f
Exploit-DB
Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated)
exploitdb·2020-10-16·CVSS 9.8
[CRITICAL] Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated)
Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated)
---
# Exploit Title: Seat Reservation System 1.0 - Unauthenticated Remote Code Execution
# Exploit Author: Rahul Ramkumar
# Date: 2020-09-16
# Vendor Homepage: www.sourcecodester.com
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/seat-reservation-system-using-php_0.zip
# Version: 1.0
# Tested On: Windows 10 Enterprise 1809 (x64_86) + XAMPP 7.2.33-1
# Exploit Tested Using: Python 2.7.18
# CVE: CVE-2020-25763
# Vulnerability Description:
# Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.
import requests, sys, urllib, re
from l
Exploit-DB
Seat Reservation System 1.0 - Unauthenticated SQL Injection
exploitdb·2020-10-16·CVSS 9.1
CVE-2020-25762 [CRITICAL] Seat Reservation System 1.0 - Unauthenticated SQL Injection
Seat Reservation System 1.0 - Unauthenticated SQL Injection
---
# Title: Seat Reservation System 1.0 - Unauthenticated SQL Injection
# Exploit Author: Rahul Ramkumar
# Date: 2020-09-16
# Vendor Homepage: www.sourcecodester.com
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/seat-reservation-system-using-php_0.zip
# Version: 1.0
# Tested On: Windows 10 Enterprise 1809 (x64_86) + XAMPP 7.2.33-1
# CVE: CVE-2020-25762
# Description
The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.
#POC
1) Navigate to the admin login page
Example:
http://192.168.1.72/s
Exploit-DB
Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
exploitdb·2020-09-24
Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
---
# Title: Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
# Exploit Author: Rahul Ramkumar
# Date: 2020-09-16
# Vendor Homepage: https://projectworlds.in
# Software Link: https://projectworlds.in/wp-content/uploads/2020/07/Visitor-Management-System-in-PHP.zip
# Version: 1.0
# Tested On: Windows 10 Enterprise 1809 (x64_86) + XAMPP 7.2.33-1
# CVE: N/A
# Description: The file myform.php does not perform input validation on the request paramters. An attacker can inject javascript payloads in the parameters to perform various attacks suchs as stealing of cookies,sensitive information etc.
import requests, sys, urllib, re
from lxml import etree
from io import StringIO
from colorama import Fore, Ba
No writeups or analysis indexed.
2020-05-29
Published