Samsung SRN-1670D Web Viewer 1.0.0.193 Arbitrary File Read / Upload

Discussion in 'News Aggregator' started by Packet Storm, 11 Jan 2018.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits an unrestricted file upload vulnerability in Web Viewer 1.0.0.193 on Samsung SRN-1670D devices. The network_ssl_upload.php file allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php extension, which is then accessed via a direct request to the file in the upload/ directory. To authenticate for this attack, one can obtain web-interface credentials in cleartext by leveraging the existing local file read vulnerability referenced by CVE-2015-8279, which allows remote attackers to read the web interface credentials by sending a request to: cslog_export.php?path=/root/php_modules/lighttpd/sbin/userpw URI.

    Continue reading...
     

Share This Page

Loading...