
39 changes to exploits/shellcodes/ghdb ProLink PRS1841 PLDT Home fiber - Default Password Nacos 2.0.3 - Access Control vulnerability sudo 1.8.0 to 1.9.12p1 - Privilege Escalation sleuthkit 4.11.1 - Command Injection Active eCommerce CMS 6.5.0 - Stored Cross-Site Scripting (XSS) ManageEngin AMP 4.3.0 - File-path-traversal SQL Monitor 12.1.31.893 - Cross-Site Scripting (XSS) AmazCart CMS 3.4 - Cross-Site-Scripting (XSS) Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS) Art Gallery Management System Project v1.0 - SQL Injection (sqli) authenticated Art Gallery Management System Project v1.0 - SQL Injection (sqli) Unauthenticated ChiKoi v1.0 - SQL Injection ERPGo SaaS 3.9 - CSV Injection GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE) GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusion GLPI v10.0.1 - Unauthenticated Sensitive Data Exposure GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration) Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS) MyBB 1.8.32 - Remote Code Execution (RCE) (Authenticated) Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection pimCore v5.4.18-skeleton - Sensitive Cookie with Improper SameSite Attribute Prizm Content Connect v10.5.1030.8315 - XXE SLIMSV 9.5.2 - Cross-Site Scripting (XSS) WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE Zstore 6.5.4 - Reflected Cross-Site Scripting (XSS) Roxy WI v6.1.0.0 - Improper Authentication Control Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload Solaris 10 libXm - Buffer overflow Local privilege escalation Chromacam 4.0.3.0 - PsyFrameGrabberService Unquoted Service Path Grand Theft Auto III/Vice City Skin File v1.1 - Buffer Overflow HotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service Path Microsoft Exchange Active Directory Topology 15.02.1118.007 - 'Service MSExchangeADTopology' Unquoted Service Path Windows 11 10.0.22000 - Backup service Privilege Escalation Windows/x86 - Create Administrator User / Dynamic PEB & EDT method null-free Shellcode (373 bytes)
47 lines
No EOL
1.2 KiB
Text
47 lines
No EOL
1.2 KiB
Text
# Exploit Title: sleuthkit 4.11.1 - Command Injection
|
|
# Date: 2023-01-20
|
|
# CVE-2022-45639
|
|
# Vendor Homepage: https://github.com/sleuthkit
|
|
# Vulnerability Type: Command injection
|
|
# Attack Type: Local
|
|
# Version: 4.11.1
|
|
# Exploit Author: Dino Barlattani, Giuseppe Granato
|
|
# Link poc: https://www.binaryworld.it/guidepoc.asp#CVE-2022-45639
|
|
# POC:
|
|
|
|
fls tool is affected by command injection in parameter "-m" when run on
|
|
linux system.
|
|
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows
|
|
attackers to execute arbitrary commands
|
|
via a crafted value to the m parameter
|
|
|
|
when it run on linux, a user can insert in the -m parameter a buffer with
|
|
backtick with a shell command.
|
|
If it run with a web application as front end it can execute commands on
|
|
the remote server.
|
|
|
|
The function affected by the vulnerability is "tsk_fs_fls()" from the
|
|
"fls_lib.c" file
|
|
|
|
#ifdef TSK_WIN32
|
|
{
|
|
....
|
|
}
|
|
#else
|
|
|
|
data.macpre = tpre; <---------------
|
|
|
|
return tsk_fs_dir_walk(fs, inode, flags, print_dent_act, &data);
|
|
|
|
#endif
|
|
|
|
Run command:
|
|
|
|
$ fls -m `id` [Options]
|
|
|
|
|
|
--
|
|
*Dino Barlattani*
|
|
www.linkedin.com/in/dino-barlattani-10bba11a9/
|
|
www.binaryworld.it <http://Binaryworld.it>
|
|
www.youtube.com/user/dinbar78 |