vendor:
Piranha Virtual Server Package
by:
patrick
N/A
CVSS
N/A
metacharacter injection vulnerability
CWE
Product Name: Piranha Virtual Server Package
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2000-0248, CVE-2000-0322
CPE:
Platforms Tested: Unix
2010
RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution
This module abuses two flaws - a metacharacter injection vulnerability in the HTTP management server of RedHat 6.2 systems running the Piranha LVS cluster service and GUI (rpm packages: piranha and piranha-gui). The vulnerability allows an authenticated attacker to execute arbitrary commands as the Apache user account (nobody) within the /piranha/secure/passwd.php3 script. The package installs with a default user and password of piranha:q which was exploited in the wild.