CVE-2020-35729: Klog Server <=2.41 - Unauthenticated Command Injection

CVE-2020-35729: Klog Server <=2.41 - Unauthenticated Command Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2020-35729: Klog Server <=2.41 - Unauthenticated Command Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-35729: KLog Server <=2.41 – Unauthenticated Command Injection

漏洞描述

Klog Server 2.4.1 and prior is susceptible to an unauthenticated command injection vulnerability. The `authenticate.php` file uses the `user` HTTP POST parameter in a call to the `shell_exec()` PHP function without appropriate input validation, allowing arbitrary command execution as the apache user. The sudo configuration permits the Apache user to execute any command as root without providing a password, resulting in privileged command execution as root. Originated from Metasploit module, copyright (c) space-r7.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享