CVE-2020-2513
published 2020-07-15CVE-2020-2513: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.66%
47.5th percentile
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_express | 5.1 – 19.2 | — |
| oracle_corporation | application_express | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_oracle5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express — CVE-2020-2513
vendor_oracle·2020-07-15·CVSS 5.4
CVE-2020-2513 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Application Express — CVE-2020-2513
Oracle Oracle Database Server Risk Matrix: Oracle Application Express vulnerability
CVE: CVE-2020-2513
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
GHSA
GHSA-fc7c-rcm4-rg4c: Vulnerability in the Oracle Application Express component of Oracle Database Server
ghsa_unreviewed·2022-05-24
CVE-2020-2513 [LOW] GHSA-fc7c-rcm4-rg4c: Vulnerability in the Oracle Application Express component of Oracle Database Server
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integr
No detection rules found.
No public exploits indexed.
Unit42
Exploits in the Wild for WordPress File Manager RCE Vulnerability (CVE-2020-25213)
blogs_unit42·2021-02-05·CVSS 5.4
CVE-2020-25213 [MEDIUM] Exploits in the Wild for WordPress File Manager RCE Vulnerability (CVE-2020-25213)
## Executive Summary
In December 2020, Unit 42 researchers observed attempts to exploit CVE-2020-25213, which is a file upload vulnerability in the WordPress File Manager plugin. Successful exploitation of this vulnerability allows an attacker to upload an arbitrary file with arbitrary names and extensions, leading to Remote Code Execution (RCE) on the targeted web server.
This exploit was used by attackers to install webshells, which in turn were used to install Kinsing, malware that runs a malicious cryptominer from the H2miner family. Kinsing is based on the Golang programming language, and its ultimate purpose is to be used in cryptojacking attacks on container environments.
Palo Alto Networks customers are protected from CVE-2020-25213 and Kinsing with Cortex XDR, AutoFocus and Nex
Unit42
Exploits in the Wild for WordPress File Manager RCE Vulnerability (CVE-2020-25213)
blogs_unit42·2021-02-05·CVSS 5.4
CVE-2020-25213 [MEDIUM] Exploits in the Wild for WordPress File Manager RCE Vulnerability (CVE-2020-25213)
Threat Research Center
Threat Research
Vulnerabilities
## Exploits in the Wild for WordPress File Manager RCE Vulnerability (CVE-2020-25213)
Nadav Markus
Efi Barkayev
Gal De Leon
Published: February 5, 2021
Threat Research
Vulnerabilities
Cryptocurrency mining
Cryptojacking
CVE-2020-25213
Kinsing
Remote Code Execution
WordPress
## Executive Summary
In December 2020, Unit 42 researchers observed attempts to exploit CVE-2020-25213 , which is a file upload vulnerability in the WordPress File Manager plugin. Successful exploitation of this vulnerability allows an attacker to upload an arbitrary file with arbitrary names and extensions, leading to Remote Code Execution (RCE) on the targeted web server.
This exploit was used by attackers to install webshells, which in turn
2020-07-15
Published