CVE-2020-11108
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.
- Affected products
- Pi-Hole
- Pi-hole
- ≤ 4.4
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 78.3% (100th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2020-05-11
CVE-2020-11108 at NVD
18 known exploits for CVE-2020-11108
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2020-11108-PoC
Exploit for Unrestricted Upload of File with Dangerous Type in Pi-Hole
NOKIA VitalSuite SPM 2020 - SQL Injection
StreamRipper32 2.6 - Buffer Overflow
Pi-hole 4.4.0 Remote Code Execution
Pi-hole 4.4.0 - Remote Code Execution (Authenticated) Exploit
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution Exploit
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
Pi-Hole heisenbergCompensator Blocklist OS Command Execution
Pi-hole < 4.4 - Remote Code Execution / Privileges Escalation Exploit
Pi-hole < 4.4 - Remote Code Execution Exploit
Pi-Hole heisenbergCompensator Blocklist OS Command Execution
Pi-hole < 4.4 - Authenticated Remote Code Execution
Pi-hole < 4.4 - Authenticated Remote Code Execution / Privileges Escalation
Pi-hole 4.4 Remote Code Execution / Privilege Escalation
Pi-hole 4.4 Remote Code Execution
Exploit for Unrestricted Upload of File with Dangerous Type in Pi-Hole