vendor:
Web Appliance
by:
patrick
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Web Appliance
Affected Version From: prior to 125.10
Affected Version To: 125.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2009
ContentKeeper Web Remote Command Execution
This module exploits the ContentKeeper Web Appliance. Versions prior to 125.10 are affected. This module exploits a combination of weaknesses to enable remote command execution as the Apache user. Following exploitation it is possible to abuse an insecure PATH call to 'ps' etc in setuid 'benetool' to escalate to root.
Mitigation:
Upgrade to ContentKeeper Web Appliance version 125.10 or later.