[CVE-2020-35846] 从 0 到 RCE:Cockpit CMS
swarm.ptsecurity.com | 研究 | CVE-2020-35846 | #rce | #vulnerability-research | #cve | #nosql-injection | #cms
摘要
开源 CMS Cockpit 的漏洞链:未认证的 NoSQL 注入(CVE-2020-35846)可通过 $eq 与 $regex 盲注技巧提取用户名,进而接管任意账户,最终实现远程代码执行。
- 发布时间
- 收录时间
Skip to content