vendor:
Junos J-Web
by:
Sense of Security Labs
5,5
CVSS
MEDIUM
Remote Code Execution Vulnerability
Not available
CWE
Product Name: Junos J-Web
Affected Version From: All builds prior to 2013-02-28
Affected Version To: All builds prior to 2013-02-28
Patch Exists: YES
Related CWE: Not yet assigned
CPE: Not available
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Junos
2013
Sense of Security – Security Advisory – SOS-13-003 security advisory
The J-Web is a GUI based network management application used on Junos devices. The web application is vulnerable to a remote code execution vulnerability which permits privilege escalation. The file/jsdm/ajax/port.php allows execution of arbitrary user supplied PHP code via the rs POST parameter. Code executes with UID=0 (root) privileges, however you are confined to a chroot. Privilege escalation can be achieved by waiting for an administrator to log in and reading the contents of /tmp to hijack their session.
Mitigation:
Disable J-Web or limit access