vendor:
MongoDB
by:
agixid
8,8
CVSS
HIGH
MongoDB nativeHelper.apply Remote Code Execution
94
CWE
Product Name: MongoDB
Affected Version From: 2.2.3
Affected Version To: 2.2.3
Patch Exists: YES
Related CWE: CVE-2013-1892
CPE: o:mongodb:mongodb:2.2.3
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2013
MongoDB nativeHelper.apply Remote Code Execution
This exploit uses the nativeHelper.apply feature in the spidermonkey mongodb implementation to execute arbitrary code. The exploit uses a combination of shellcode and ropchain to execute the code.
Mitigation:
Upgrade to the latest version of MongoDB.