vendor:
Quick Time Stream Server
by:
FOX_MULDER
7,5
CVSS
HIGH
Remote Root Compromise
78
CWE
Product Name: Quick Time Stream Server
Affected Version From: Darwin 4.x
Affected Version To: Darwin 5.X
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Darwin
2003
QTTS REMOTE ROOT EXPLOIT BY FOX_MULDER
The bug in Darwin 5.X with unpatched QTSS in parse_xml.cgi which lead to remote root compromise. This exploit is based on http://wbyte.ath.cx/~wbyte/researches/qtss-core.txt#
Mitigation:
Patch the QTSS server to the latest version