これは、CVE-2020-0618 を検出するためのシンプルなPoCです。この脆弱性は、Microsoft SQL Server Reporting Services (SSRS) に影響を与えるリモートコード実行の脆弱性です。
この脆弱性は、LoadReport() SOAP API における不適切なパス検証に起因します。脆弱な場合、SQL Server Reporting Services アカウントのコンテキストでリモートコード実行につながる可能性があります。
requests Python ライブラリpython3 cve_2020_0618_poc.py <target_URL>
python3 cve_2020_0618_poc.py http://xxx.xxx.xxx.xx/ReportServer/