Sploitus

CVE-2020-11108

18 known exploits for CVE-2020-11108

The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.

Affected products
Pi-Hole
Pi-hole
≤ 4.4
Fix
Available
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
78.3% (100th percentile)
Weakness
CWE-434
NVD status
Modified
Published
2020-05-11
CVE-2020-11108 at NVD
Authoritative description, scoring and affected products

18 known exploits for CVE-2020-11108

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2020-11108-PoC
2026-08-28 KitPloitKITPLOIT
Exploit for Unrestricted Upload of File with Dangerous Type in Pi-Hole
2021-07-23 jurafishGITEE
NOKIA VitalSuite SPM 2020 - SQL Injection
2020-05-30 0daydb.comUNKNOWN
StreamRipper32 2.6 - Buffer Overflow
2020-05-30 0daydb.comUNKNOWN
Pi-hole 4.4.0 Remote Code Execution
2020-05-27 PhotubiasPACKETSTORMPerl
Pi-hole 4.4.0 - Remote Code Execution (Authenticated) Exploit
2020-05-26 PhotubiasZDTPerl
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
2020-05-26 PhotubiasEXPLOITDBPerl
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution Exploit
2020-05-19 metasploitZDTRuby
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
2020-05-19 MetasploitEXPLOITDBRuby
Pi-Hole heisenbergCompensator Blocklist OS Command Execution
2020-05-18 h00diePACKETSTORMRuby
Pi-hole < 4.4 - Remote Code Execution / Privileges Escalation Exploit
2020-05-11 Nick FrichetteZDTPython
Pi-hole < 4.4 - Remote Code Execution Exploit
2020-05-11 Nick FrichetteZDTPython
Pi-Hole heisenbergCompensator Blocklist OS Command Execution
2020-05-10 h00die, Nick FrichetteMETASPLOITRuby
Pi-hole < 4.4 - Authenticated Remote Code Execution
2020-05-10 Nick FrichetteEXPLOITDBPython
Pi-hole < 4.4 - Authenticated Remote Code Execution / Privileges Escalation
2020-05-10 Nick FrichetteEXPLOITDBPython
Pi-hole 4.4 Remote Code Execution / Privilege Escalation
2020-05-10 Nick FrichettePACKETSTORMPython
Pi-hole 4.4 Remote Code Execution
2020-05-10 Nick FrichettePACKETSTORMPython
Exploit for Unrestricted Upload of File with Dangerous Type in Pi-Hole
2020-04-04 FrichettenGITHUB