vendor:
OpenPLI - Dream Multimedia Box with OpenPLI software
by:
Michael Messner
8,8
CVSS
HIGH
OS Command Execution, stored XSS
78, 79
CWE
Product Name: OpenPLI - Dream Multimedia Box with OpenPLI software
Affected Version From: v3.0 beta (OpenPLi-beta-dm7000-20130127-272)
Affected Version To: v3.0 beta (OpenPLi-beta-dm7000-20130127-272)
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2013
Multiple Vulnerabilities in OpenPLI
The vulnerability is caused by missing input validation in the maxmtu parameter and can be exploited to inject and execute arbitrary shell commands. It is possible to use Netcat to fully compromise the device. Injecting scripts into the parameter xxx reveals that this parameter is not properly validated for malicious input.
Mitigation:
No known solution available.