The attack involves tricking a privileged user to initiate a request by clicking a malicious link or visiting an evil webpage to shutdown WSO2 Servers.
An authenticated user can download configuration files in the filesystem via downloadArchivedLogFiles operation in LogViewer admin service. The request to the admin service accepts a file path relative to the carbon log file directory (i.e. <WSO2_PRODUCT_HOME>/repository/logs) hence can access any file in the file system.
WSO2IS XML parser is vulnerable to XXE attack in the XACML flow, this can be exploited when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack leads to the disclosure and exfiltration of confidential data and arbitrary system files, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located (localhost), and other system impacts.
The specific flaw exists within the parsing of invalid operand in “sprmSdyaTop” into a SEPX structure. An attacker can use this flaw to re-allocate memory and execute arbitrary code under the context of the current process.
Zabbix 2.2.x, 3.0.x and trunk suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the toggle_ids array in the latest.php page. By exploiting this SQL injection vulnerability, an authenticated attacker (or guest user) is able to gain full access to the database. This would allow an attacker to escalate their privileges to a power user, compromise the database, or execute commands on the underlying database operating system. Although the attacker needs to be authenticated in general, the system could also be at risk if the adversary has no user account. Zabbix offers a guest mode which provides a low privileged default account for users without password. If this guest mode is enabled, the SQL injection vulnerability can be exploited unauthenticated.
Any registered user can "log in" as any other user, including administrators. A crafted request using the current authenticity token can be used to impersonate any user.
This exploit is used to change the web and root passwords of Samsung Smart Camera using the unauthenticated vulnerability found by zenofex. The exploit uses command injection to run a command on the device and convert a normal command into one using bash brace expansion. It then uses HTTP digest auth for urllib2 and uses sed to search and replace the old for new hash in the passwd.
A vulnerability in FreePBX 13 and 14 allows an unauthenticated attacker to execute arbitrary code as root. This vulnerability is due to a lack of input validation in the System Recordings Module versions 13.0.1beta1 - 13.0.26. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server.
Vulnerabilities were found in the extraction of specially crafted archive files, that could lead to local denial of service conditions or privilege escalation.
ZOHO WebNMS Framework before version 5.2 SP1 is vulnerable local file inclusion which allows an attacker to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.