
PoC léger en Python pour détecter la vulnérabilité d'exécution de code à distance CVE-2020-0618 dans Microsoft SQL Server Reporting Services via une vérification de validation de chemin de l'API SOAP.
Ceci est un simple PoC pour détecter CVE-2020-0618, une vulnérabilité d'exécution de code à distance affectant Microsoft SQL Server Reporting Services (SSRS).
La vulnérabilité existe en raison d'une validation de chemin incorrecte dans l'API SOAP LoadReport(). Si vulnérable, cela pourrait potentiellement conduire à une exécution de code à distance dans le contexte du compte SQL Server Reporting Services.
requestspython3 cve_2020_0618_poc.py <target_URL>
python3 cve_2020_0618_poc.py http://xxx.xxx.xxx.xx/ReportServer/