vendor:
OpenBase 10.0
by:
kf
9,3
CVSS
HIGH
Command Injection
78
CWE
Product Name: OpenBase 10.0
Affected Version From: 10.0.0
Affected Version To: 10.0.0
Patch Exists: Yes
Related CWE: N/A
CPE: a:openbase:openbase_10.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MacOSX
2006
OpenBase 10.0 Remote Root Exploit
This exploit is a proof of concept for a command injection vulnerability in OpenBase 10.0. The exploit uses system() to execute arbitrary commands with root privileges. The exploit is triggered by using the flags -install, -kill, and -uninstall with the openexec binary.
Mitigation:
Update to the latest version of OpenBase 10.0