header-logo
Suggest Exploit
vendor:
Splunk
by:
@marcwickenden, sinn3r, juan vazquez
7,5
CVSS
HIGH
Remote Code Execution
N/A
CWE
Product Name: Splunk
Affected Version From: Splunk 5.0.1
Affected Version To: Splunk 5.0.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Windows
2012

Splunk 5.0 Custom App Remote Code Execution

This module exploits a feature of Splunk whereby a custom application can be uploaded through the web based interface. Through the 'script' search command a user can call commands defined in their custom application which includes arbitrary perl or python code. To abuse this behavior, a valid Splunk user with the admin role is required. By default, this module uses the credential of 'admin:changeme', the default Administrator credential for Splunk. Note that the Splunk web interface runs as SYSTEM on Windows, or as root on Linux by default. This module has only been tested successfully against Splunk 5.0.

Mitigation:

Restrict access to Splunk web interface and use strong credentials.
Source

Exploit-DB raw data: