Barracuda Web App Firewall/Load Balancer Post Auth Remote Root Exploit (2)

Discussion in 'News Aggregator' started by Packet Storm, 27 Jul 2016.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a remote command execution vulnerability in the Barracuda Web App Firewall Firmware Version <= 8.0.1.007 and Load Balancer Firmware <= v5.4.0.004 by exploiting a two vulnerabilities in the web administration interface. The first bug leverages a Arbitrary File Upload vulnerability to create a malicious file containing shell commands before using a second bug meant to clean up left-over core files on the device to execute them. By sending a specially crafted requests it's possible to inject system commands while escalating to root do to relaxed sudo configurations on the appliances.

    Continue reading...
     

Share This Page

Loading...