PT-2017-14439 · Unknown+1 · Web Viewer+1

0Xffffff

+1

·

Published

2017-11-06

·

Updated

2017-11-29

·

CVE-2017-16524

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Web Viewer version 1.0.0.193
Description The issue allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the "network ssl upload.php" endpoint. This is achieved by accessing the uploaded file directly in the upload/ directory. Authentication for this attack can be obtained by leveraging an existing Local File Read issue, which allows remote attackers to read web-interface credentials in cleartext via a request to the "cslog export.php?path=/root/php modules/lighttpd/sbin/userpw" URI.
Recommendations For Web Viewer version 1.0.0.193, restrict access to the "network ssl upload.php" endpoint to prevent arbitrary PHP code execution. As a temporary workaround, consider disabling the upload functionality in the "network ssl upload.php" endpoint until a patch is available. Additionally, restrict access to the "cslog export.php" endpoint to minimize the risk of credential exposure.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16524

Affected Products

Web Viewer
Lighttpd