vendor:
NetCharts Server
by:
sghctoma, juan vazquez
9,8
CVSS
CRITICAL
Arbitrary JSP Code Upload
79
CWE
Product Name: NetCharts Server
Affected Version From: Visual Mining NetCharts Server 7.0
Affected Version To: Visual Mining NetCharts Server 7.0
Patch Exists: YES
Related CWE: CVE-2014-8516, ZDI-14-372
CPE: a:visual_mining:netcharts_server:7.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Windows
2014
Visual Mining NetCharts Server Remote Code Execution
This module exploits multiple vulnerabilities in Visual Mining NetCharts. First, a lack of input validation in the administration console permits arbitrary jsp code upload to locations accessible later through the web service. Authentication is typically required, however a 'hidden' user is available by default (and non editable). This user, named 'Scheduler', can only login to the console after any modification in the user database (a user is added, admin password is changed etc). If the 'Scheduler' user isn't available valid credentials must be supplied. The default Admin password is Admin.
Mitigation:
Input validation should be implemented to prevent arbitrary JSP code upload.