IPFire < 2.19 Core Update 101 proxy.cgi RCE
36Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendcvss 8.7epss 1.2%
de la publicación al arma0 días
Publicada en NVD15 jul
metasploit4 may
probabilidad de explotación
1.2%top 35% de las CVE
explotación observada
noninguna fuente lo reporta
A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated attacker can inject arbitrary shell commands through crafted values in the NCSA user creation form fields, leading to command execution with web server privileges.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
IPFire Project · IPFireReferencias
https://bugzilla.ipfire.org/show_bug.cgi?id=11087https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/ipfire_proxy_exec.rbhttps://www.asafety.fr/en/vuln-exploit-poc/xss-rce-ipfire-2-19-core-update-101-remote-command-execution/https://www.exploit-db.com/exploits/39765https://www.ipfire.org/news/ipfire-2-19-core-update-101-releasedhttps://www.vulncheck.com/advisories/ipfire-authenticated-rce