vendor:
LiteSpeed WebServer
by:
Kingcope
7,5
CVSS
HIGH
Remote Exploit
78
CWE
Product Name: LiteSpeed WebServer
Affected Version From: 4.0.17
Affected Version To: 4.0.15
Patch Exists: YES
Related CWE: N/A
CPE: a:litespeed_technologies:litespeed_webserver
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 8.0-RELEASE, FreeBSD 6.3-RELEASE and FreeBSD 8.0-RELEASE
2010
LiteSpeed Web Server 4.0.17 w/ PHP Remote Exploit for FreeBSD
This exploit is a proof of concept, which can be used against the admin interface (port 7080) of LiteSpeed Web Server 4.0.17 Standard & Enterprise x86 on FreeBSD 8.0-RELEASE, FreeBSD 6.3-RELEASE and FreeBSD 8.0-RELEASE - LiteSpeed WebServer 4.0.15 Standard x86. It can also be used against the compiled SAPI version of the shipped linux version of lsphp, but the offsets differ from box to box. The exploit buffer contains a setreuid, connect back, and a reverse shell port 443.
Mitigation:
Upgrade to the latest version of LiteSpeed Web Server and ensure that the server is configured securely.