Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-5722 PoC — Grandstream UCM6200 SQL注入漏洞

Source
Associated Vulnerability
Title:Grandstream UCM6200 SQL注入漏洞 (CVE-2020-5722)
Description:Grandstream UCM6200是美国潮流网络(Grandstream)公司的一套用于IP电话通信的企业级交换机。 Grandstream UCM6200 1.0.19.20之前版本和1.0.20.17之前版本中的HTTP接口存在SQL注入漏洞。攻击者可利用该漏洞以root权限执行shell命令或向密码找回邮件中注入HTML。
Description
Grandstream UCM6200 series contains an unauthenticated remote SQL injection caused by crafted HTTP requests, letting attackers execute shell commands as root on versions before 1.0.19.20 or inject HTML in emails before 1.0.20.17.
File Snapshot

id: CVE-2020-5722 info: name: Grandstream UCM6200 - SQL Injection author: theamanrawat severi ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.