PT-2016-3222 · Dnalims · Dnalims

H00Die

+2

·

Publicado

2016-11-06

·

Atualizado

2019-10-03

·

CVE-2017-6526

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dnaLIMS version 4-2015s13
Description The issue concerns an improperly protected administrative web shell, allowing unauthenticated command execution. This can be exploited through cgi-bin/dna/sysAdmin.cgi using specially crafted POST requests, enabling a remote attacker to execute arbitrary commands. The vulnerability is related to the lack of input data sanitization measures in the administrative web shell of the dnaLIMS software.
Recommendations For dnaLIMS version 4-2015s13, consider disabling access to the cgi-bin/dna/sysAdmin.cgi endpoint until a patch is available to prevent exploitation. Restricting access to this administrative web shell can help minimize the risk of command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02590
CVE-2017-6526

Produtos afetados

Dnalims