跳转到帖子

CrushFTP Unauthenticated RCE

recommended_posts

发布于
  • Members

CrushFTP Unauthenticated RCE

Disclosed
08/08/2023
Created
04/12/2024

Description

This exploit module leverages an Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability (CVE-2023-43177) to achieve unauthenticated remote code execution. This affects CrushFTP versions prior to 10.5.1. It is possible to set some user's session properties by sending an HTTP request with specially crafted Header key-value pairs. This enables an unauthenticated attacker to access files anywhere on the server file system and steal the session cookies of valid authenticated users. The attack consists in hijacking a user's session and escalates privileges to obtain full control of the target. Remote code execution is obtained by abusing the dynamic SQL driver loading and configuration testing feature.

Author(s)

  • Ryan Emmons
  • Christophe De La Fuente

Platform

Java,Linux,Unix,Windows

Architectures

java, x64, x86

Development

  • Source Code
  • History
  • 查看数 699
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…